Weaknesses of type CWE-200

4,948 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-24373MEDIUMUnrestricted Access to PDF Documents via URL Manipulation in woocommerce-pdf-invoices-packing-slipsEPSS 0.4%CVE-2025-70829MEDIUMAn information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC conEPSS 0.4%CVE-2024-12140MEDIUMElementor AI Addons – 70 Widgets, Premium Templates, Ultimate Elements <= 2.2.1 - Authenticated (Contributor+) Private Templates Content DisclosureEPSS 0.4%CVE-2021-46891—Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affeEPSS 0.4%CVE-2021-36096MEDIUMSupport Bundle includes S/Mime and PGP secret or PINEPSS 0.4%CVE-2023-41676MEDIUMAn exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker wEPSS 0.4%CVE-2026-9836LOWIBM DataStage Flow Designer application is affected by an information disclosure vulnerabilityEPSS 0.4%CVE-2020-9846—A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be ablEPSS 0.4%CVE-2024-6570MEDIUMGlossary <= 2.2.26 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-84135CRITICALOther issue in Firefox Focus for AndroidEPSS 0.4%CVE-2026-54553MEDIUMStarlette-Admin: Unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoSEPSS 0.4%CVE-2024-6567MEDIUMEbook Store <= 5.8001 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-34984HIGHExternal Secrets Operator has DNS exfiltration via getHostByName in its v2 template engineEPSS 0.4%CVE-2024-6546MEDIUMOne Click Close Comments <= 2.7.1 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-43289HIGHWordPress wpForo Forum plugin <= 2.3.4 - Unauthenticated Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2023-3455—Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.EPSS 0.4%CVE-2026-78378MEDIUMRedis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook DataEPSS 0.4%CVE-2024-38761HIGHWordPress Zephyr Project Manager plugin <= 3.3.99 - Sensitive Data Exposure via Export File vulnerabilityEPSS 0.4%CVE-2024-38747HIGHWordPress HitPay Payment Gateway for WooCommerce plugin <= 4.1.3 - Sensitive Data Exposure via Log File vulnerabilityEPSS 0.4%CVE-2024-13525MEDIUMCustomer Email Verification for WooCommerce <= 2.9.4 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%