Weaknesses of type CWE-200

4,949 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-21579HIGHThis High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2EPSS 0.4%CVE-2024-7415MEDIUMRemember Me Controls <= 2.0.1 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-21685HIGHThis High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. EPSS 0.4%CVE-2024-6499MEDIUMWordPress Button Plugin MaxButtons <= 9.7.8 - Full Path DisclosureEPSS 0.4%CVE-2024-6552MEDIUMBooking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-56242HIGHCapgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_identity_apikey_only RPCEPSS 0.4%CVE-2026-93685MEDIUMMulticluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.newcontrollercommandconfig (confirmed exposed by engineering)EPSS 0.4%CVE-2024-6557MEDIUMSchedulePress <= 5.1.3 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-67972HIGHAn issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possiblyEPSS 0.4%CVE-2026-55088MEDIUMEtherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author tokenEPSS 0.4%CVE-2025-11670MEDIUMNTLM Hash Exposure VulnerabilityEPSS 0.4%CVE-2026-25222MEDIUMPolarLearn Affected by User Enumeration via Argon2 Timing Attack on Sign-In EndpointEPSS 0.4%CVE-2024-6565MEDIUMAForms <= 2.2.6 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-5614MEDIUMPiotnet Addons For Elementor <= 2.4.29 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2026-84130HIGHInformation disclosure in the Graphics: WebGPU componentEPSS 0.4%CVE-2026-34579MEDIUMMantisBT has an authorization bypass via private issue monitoringEPSS 0.4%CVE-2022-30735MEDIUMImproper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permissioEPSS 0.4%CVE-2026-33882MEDIUMStatamic's Markdown preview endpoint exposes sensitive user dataEPSS 0.4%CVE-2024-22002HIGHCORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the instaEPSS 0.4%CVE-2026-88876HIGHAVideo PlayerSkins seo.php Missing Authorization Password-Protected VODEPSS 0.4%