Weaknesses of type CWE-200

4,941 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-32265MEDIUMAmazon S3 for Craft CMS has an Information Disclosure vulnerabilityEPSS 0.5%CVE-2026-53553HIGHGoploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server CompromiseEPSS 0.5%CVE-2024-6568MEDIUMFlamix: Bitrix24 and Contact Form 7 integrations <= 3.1.0 - Unauthenticated Full Path DisclosureEPSS 0.5%CVE-2020-36850HIGHSitecore JSS React Sample Application 11.0.0 - 14.0.1 Information DisclosureEPSS 0.5%CVE-2025-69755HIGHAn issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary coEPSS 0.5%CVE-2023-1562LOWFull name revealed via /plugins/focalboard/api/v2/usersEPSS 0.5%CVE-2025-25975HIGHAn issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys functionEPSS 0.5%CVE-2024-41264HIGHAn issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.EPSS 0.5%CVE-2024-8969MEDIUMThe SYSCOM Group OMFLOW - Exposure of Sensitive DataEPSS 0.5%CVE-2025-25281HIGHOutback Power Mojave Inverter Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.5%CVE-2025-22973HIGHAn issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/applicationEPSS 0.5%CVE-2026-33355MEDIUMDiscourse filters whisper posts from private-posts feedEPSS 0.5%CVE-2026-87792HIGHMultiple authorization bypass in WordPress theme design-scuole-wordpress-themeEPSS 0.5%CVE-2026-101055MEDIUMThinkware U3000 TCP Service GET_STATUS information disclosureEPSS 0.5%CVE-2026-73775HIGHAuthenticated Sensitive Information Disclosure Vulnerabilities in AOS-CXEPSS 0.5%CVE-2026-28492HIGHFile Browser: Path Traversal in Public Share Links Exposes Files Outside Shared DirectoryEPSS 0.5%CVE-2022-0854—A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to EPSS 0.5%CVE-2023-2749HIGHA Gain Information vulnerability was found on Download Center.EPSS 0.5%CVE-2026-76697MEDIUMAuthenticated Information Disclosure in HPE Networking EdgeConnect Enterprise Web-Based Management InterfaceEPSS 0.5%CVE-2026-59222MEDIUMOpen WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentialsEPSS 0.5%