Weaknesses of type CWE-200

4,941 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-39358MEDIUMMetabase vulnerable to circumvention of Locked parameter in Signed EmbeddingEPSS 0.5%CVE-2024-0906MEDIUMf(x) Private Site <= 1.2.1 - Sensitive Information ExposureEPSS 0.5%CVE-2021-46841—This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.5.0 for Android. An EPSS 0.5%CVE-2024-13623MEDIUMOrder Export for WooCommerce <= 3.24 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.5%CVE-2025-65820CRITICALAn issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mobile application whicEPSS 0.5%CVE-2026-67100CRITICALHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.5%CVE-2025-59209MEDIUMWindows Push Notification Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-0883MEDIUMInformation disclosure in the Networking componentEPSS 0.5%CVE-2026-24473MEDIUMHono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)EPSS 0.5%CVE-2026-58427HIGHPrivate org member list leaked via /members API endpoint — incomplete fix for PR #38145EPSS 0.5%CVE-2026-51995HIGHAn issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-sEPSS 0.5%CVE-2026-27161HIGHUnauthenticated Information Disclosure via .htaccess Reliance in Sensitive DirectoriesEPSS 0.5%CVE-2024-13604HIGHKB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin <= 1.7.4 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.5%CVE-2023-31404MEDIUMInformation Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Service)EPSS 0.5%CVE-2026-86895HIGHAn information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOSEPSS 0.5%CVE-2026-58434HIGHPrivate Repository Metadata Remains Accessible After Access RevocationEPSS 0.5%CVE-2026-32266LOWGoogle Cloud Storage for Craft CMS has an Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-56267MEDIUMFlowise - PII Disclosure via Unauthenticated Forgot Password EndpointEPSS 0.5%CVE-2022-32244—Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) sysEPSS 0.5%CVE-2026-1196LOWMineAdmin getFileInfoById information disclosureEPSS 0.5%