Weaknesses of type CWE-200

4,949 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-20457MEDIUMCisco Unified Communications Manager IM & Presence Service Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-74948MEDIUMInformation disclosure in the Graphics componentEPSS 0.4%CVE-2024-20445MEDIUMCisco IP Phone 7800, 8800, and 9800 Series Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-74945MEDIUMInformation disclosure in the Graphics: Text componentEPSS 0.4%CVE-2023-48957MEDIUMPureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to EPSS 0.4%CVE-2024-8516MEDIUMThemesflat Addons For Elementor <= 2.2.1 - Authenticated (Contributor+) Information ExposureEPSS 0.4%CVE-2023-7046HIGHWP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score <= 7.0 - Sensitive Information Exposure via insufficiently protected filesEPSS 0.4%CVE-2022-20955MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software VulnerabilitiesEPSS 0.4%CVE-2026-63461MEDIUMVendure: Shop API list queries can return non-public entities when filterOperator is OREPSS 0.4%CVE-2023-48296MEDIUMOroPlatform's storefront user can access history and most viewed data from matching back-office user with the same IDEPSS 0.4%CVE-2023-45824MEDIUMOroPlatform's pinned entity creation form shows pages of other usersEPSS 0.4%CVE-2022-20954MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software VulnerabilitiesEPSS 0.4%CVE-2025-62669MEDIUMUserInfoCard: activeLocalBlocksAllWikis does not do permissions checksEPSS 0.4%CVE-2024-35776MEDIUMWordPress phpinfo() WP plugin <= 5.0 - Unauthenticated Data Exposure vulnerabilityEPSS 0.4%CVE-2023-25169LOWYearly Review Plugin leaking anonymised users data in discourse-yearly-reviewEPSS 0.4%CVE-2024-6547MEDIUMAdd Admin CSS <= 2.0.1 - Unauthenticated Full Path DislcosureEPSS 0.4%CVE-2024-7411MEDIUMNewsletters <= 4.9.9 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-84132HIGHInformation disclosure in the Networking: HTTP componentEPSS 0.4%CVE-2026-34744MEDIUMMantisBT authorization bypass allows continued access to self-uploaded attachments on private issuesEPSS 0.4%CVE-2024-6573MEDIUMIntelligence <= 1.4.0 - Unauthenticated Full Path DisclosureEPSS 0.4%