Weaknesses of type CWE-200

4,949 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-35223MEDIUMDapr API Token ExposureEPSS 0.4%CVE-2026-48786MEDIUMFleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpointEPSS 0.4%CVE-2026-3504MEDIUMDokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API EndpointEPSS 0.4%CVE-2026-61842MEDIUMGrav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)EPSS 0.4%CVE-2023-23628MEDIUMMetabase subject to Exposure of Sensitive Information to an Unauthorized Actor EPSS 0.4%CVE-2026-47364MEDIUMIn versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no userEPSS 0.4%CVE-2024-10312MEDIUMExclusive Addons for Elementor <= 2.7.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesEPSS 0.4%CVE-2026-88876HIGHAVideo PlayerSkins seo.php Missing Authorization Password-Protected VODEPSS 0.4%CVE-2024-22002HIGHCORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the instaEPSS 0.4%CVE-2026-33882MEDIUMStatamic's Markdown preview endpoint exposes sensitive user dataEPSS 0.4%CVE-2026-75523MEDIUMSteeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secretsEPSS 0.4%CVE-2026-73883HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.4%CVE-2026-34297HIGHVulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versioEPSS 0.4%CVE-2024-22435HIGHHPE NonStop Web ViewPoint Enterprise software, Unauthorized accessEPSS 0.4%CVE-2026-73878HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.4%CVE-2024-55951MEDIUMMetabase sandboxed users could see filter values from other sandboxed usersEPSS 0.4%CVE-2026-73884HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.4%CVE-2026-60167HIGHVulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions thatEPSS 0.4%CVE-2026-60556HIGHVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are aEPSS 0.4%CVE-2026-61159HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience MaEPSS 0.4%