Weaknesses of type CWE-200

4,898 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2021-41532—Unauthenticated access to Ozone Recon HTTP endpointsEPSS 2.4%CVE-2026-2262HIGHEasy Appointments <= 3.12.21 - Unauthenticated Sensitive Information Exposure via REST APIEPSS 2.4%CVE-2021-39856MEDIUMAdobe Acrobat Reader DC NTLMv2 SSO Information Disclosure via LoadFileEPSS 2.4%CVE-2021-39855MEDIUMAdobe Acrobat Reader DC NTLMv2 SSO Information Disclosure via src ParameterEPSS 2.4%CVE-2025-9209CRITICALRestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWTEPSS 2.3%CVE-2025-12139HIGHFile Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information ExposureEPSS 2.3%CVE-2017-6626—A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and 11.6(1) could allowEPSS 2.3%CVE-2020-8216—An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting detailsEPSS 2.3%CVE-2018-0245—A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote EPSS 2.3%CVE-2026-34472HIGHUnauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attacEPSS 2.3%CVE-2024-12008MEDIUMW3 Total Cache <= 2.8.1 Information Exposure via Log FilesEPSS 2.3%CVE-2021-21323MEDIUMRegression in DNS leakage from Tor windowsEPSS 2.3%CVE-2017-12354—A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to viEPSS 2.2%CVE-2024-8929MEDIUMLeak partial content of the heap through heap buffer over-read in mysqlndEPSS 2.2%CVE-2026-4020HIGHGravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST APIEPSS 2.2%CVE-2020-15098HIGHMissing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMSEPSS 2.2%CVE-2022-23633HIGHExposure of sensitive information in Action PackEPSS 2.2%CVE-2020-8151—There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requestEPSS 2.2%CVE-2020-3411HIGHCisco DNA Center Information Disclosure VulnerabilityEPSS 2.2%CVE-2023-28322MEDIUMAn information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callbackEPSS 2.2%