Weaknesses of type CWE-200

4,941 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-56300HIGHCapgo - Unauthenticated API Key Validity and Permission Oracle via RPC FunctionsEPSS 0.5%CVE-2026-56303HIGHCapgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC FunctionEPSS 0.5%CVE-2024-34004MEDIUMmoodle: authenticated LFI risk in some misconfigured shared hosting environments via modified mod_wiki backupEPSS 0.5%CVE-2023-28175HIGHImproper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within theEPSS 0.5%CVE-2023-48732MEDIUMKeywords that trigger mentions are leaked to other usersEPSS 0.5%CVE-2026-92917HIGHGrav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_rEPSS 0.5%CVE-2026-50416LOWWin32k Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-43988HIGHKuWFi 5G01-X55 FL2020_V0.0.12 devices expose an unauthenticated API endpoint (ajax_get.cgi), allowing remote attackers to retrieve sensitiveEPSS 0.5%CVE-2023-37239—Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to cEPSS 0.5%CVE-2026-50419LOWWindows Kernel Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-59256HIGHWWBN AVideo Unbound Token Authorization Bypass via GalleryEPSS 0.5%CVE-2022-39397MEDIUMExposure of sensitive information in aliyun-oss-clientEPSS 0.5%CVE-2026-62960HIGHGit for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on WindowsEPSS 0.5%CVE-2026-69224MEDIUMinformation disclosure vulnerability in Esri Portal for ArcGISEPSS 0.5%CVE-2024-53359HIGHAn issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.EPSS 0.5%CVE-2024-30381HIGHParagon Active Assurance: probe_serviced exposes internal objects to local usersEPSS 0.5%CVE-2026-84990HIGHntopng: Missing Authorization on System Configuration Backup Download and ListingEPSS 0.5%CVE-2026-22645MEDIUMThe application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity EPSS 0.5%CVE-2026-69225MEDIUMinformation disclosure vulnerability in Esri Portal for ArcGISEPSS 0.5%CVE-2026-48009MEDIUMShopware: Admin Account Takeover via User Recovery Hash ExposureEPSS 0.5%