Weaknesses of type CWE-200

4,941 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-41087MEDIUMWindows File Explorer Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-50409MEDIUMWindows Overlay Filter Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-50681MEDIUMWindows Secure Channel Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-33842MEDIUMWindows File Explorer Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-50339MEDIUMWindows Push Notification Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-47642MEDIUMStream description leaks to ex-subscribers in ZulipEPSS 0.5%CVE-2026-61426HIGHPraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure DefaultsEPSS 0.5%CVE-2024-7630MEDIUMRelevanssi <= 4.22.2 (Free) and <= 2.25.1 (Premium) - Unauthenticated Information ExposureEPSS 0.5%CVE-2022-47892MEDIUMInformation disclosure in NetMan 204EPSS 0.5%CVE-2026-70491MEDIUMOpen WebUI: Tool source code disclosed to read-only users via the tool list and get endpointsEPSS 0.5%CVE-2026-4957MEDIUMOpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log fileEPSS 0.5%CVE-2024-1406MEDIUMLinksys WRT54GL Web Management Interface SysInfo1.htm information disclosureEPSS 0.5%CVE-2024-40862HIGHA privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attacker may be able to determine the Apple IDEPSS 0.5%CVE-2026-88059MEDIUMAngular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`EPSS 0.5%CVE-2026-82651MEDIUMSiYuan before v3.8.1 Missing Authorization via /history and /repo/diffEPSS 0.5%CVE-2023-42666MEDIUMExposure of Sensitive Information to an Unauthorized Actor in DEXMA DEXGateEPSS 0.5%CVE-2024-10965MEDIUMemqx neuron JSON File schema information disclosureEPSS 0.5%CVE-2022-3185MEDIUMDataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensitive data concerning EPSS 0.5%CVE-2022-46158MEDIUMPotential Information exposure in the upload directory in PrestaShopEPSS 0.5%CVE-2025-20345MEDIUMCisco Duo Authentication Proxy Information Disclosure VulnerabilityEPSS 0.5%