Weaknesses of type CWE-200

4,942 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-69224MEDIUMinformation disclosure vulnerability in Esri Portal for ArcGISEPSS 0.5%CVE-2026-5413MEDIUMNewgen OmniDocs GetWebApiConfiguration information disclosureEPSS 0.5%CVE-2026-40965CRITICALCloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC EPSS 0.5%CVE-2021-37939—It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, whichEPSS 0.5%CVE-2022-45167MEDIUMAn issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user to access the profiEPSS 0.5%CVE-2025-58445MEDIUMAtlantis Exposes Service Version Publicly on /status API EndpointEPSS 0.5%CVE-2026-18673MEDIUMKong Mesh: the kuma-dp readiness service exposes the Envoy admin API without authenticationEPSS 0.5%CVE-2026-45286MEDIUMNextcloud: Calendar app leaked user identifiers via attendee suggestion endpointEPSS 0.5%CVE-2024-11090MEDIUMMembership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.5%CVE-2023-22813LOWDevice API endpoint missing access controls on Western Digital Mobile and Web AppsEPSS 0.5%CVE-2024-11290MEDIUMMember Access <= 1.1.6 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.5%CVE-2024-24748MEDIUMDisclosure of the existence of secret subcategories in DiscourseEPSS 0.5%CVE-2022-23490MEDIUMImproper access control to polling votesEPSS 0.5%CVE-2023-45809LOWDisclosure of user names via admin bulk action views in wagtailEPSS 0.5%CVE-2024-31490MEDIUMAn exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1EPSS 0.5%CVE-2024-0708MEDIUMLanding Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages <= 1.7.2 - Unauthenticated Information ExposureEPSS 0.5%CVE-2025-10952MEDIUMgeyang ml-logger File server.py stream_handler information disclosureEPSS 0.5%CVE-2024-42351MEDIUMPossible Data Tampering & Loss of Public Datasets in GalaxyEPSS 0.5%CVE-2026-59216HIGHOpen WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_idEPSS 0.5%CVE-2024-24867MEDIUMWordPress WP Stats Manager plugin <= 6.9.4 - Sensitive Data Exposure vulnerabilityEPSS 0.5%