Weaknesses of type CWE-200

4,898 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-21308MEDIUMWindows Themes Spoofing VulnerabilityEPSS 2.2%CVE-2023-49282MEDIUMTest code in published microsoft-graph package exposes phpinfo()EPSS 2.2%CVE-2023-49283MEDIUMTest code in published microsoft-graph-core package exposes phpinfo()EPSS 2.2%CVE-2018-15446MEDIUMCisco Meeting Server Information Disclosure VulnerabilityEPSS 2.2%CVE-2023-40211HIGHWordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data ExposureEPSS 2.2%CVE-2024-38041MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 2.2%CVE-2021-29115MEDIUMAn information disclosure vulnerabilityEPSS 2.1%CVE-2024-42049CRITICALTightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.EPSS 2.1%CVE-2020-1699HIGHA path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has beeEPSS 2.1%CVE-2024-43609MEDIUMMicrosoft Office Spoofing VulnerabilityEPSS 2.1%CVE-2023-36763HIGHMicrosoft Outlook Information Disclosure VulnerabilityEPSS 2.1%CVE-2018-0278—A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensiEPSS 2.1%CVE-2019-5017MEDIUMAn exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module that enables the ReadySHARE Printer functioEPSS 2.1%CVE-2018-14642MEDIUMAn information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that hanEPSS 2.1%CVE-2018-10890MEDIUMA flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to reEPSS 2.1%CVE-2022-23634HIGHInformation Exposure when using Puma with RailsEPSS 2.1%CVE-2024-8460MEDIUMD-Link DNS-320 Web Management Interface widget_api.cgi information disclosureEPSS 2.1%CVE-2025-11693CRITICALExport WP Page to Static HTML & PDF <= 4.3.4 - Unauthenticated Cookie Exposure via Log FileEPSS 2.1%CVE-2021-29450MEDIUMWordPress Authenticated disclosure of password-protected posts and pagesEPSS 2.1%CVE-2017-15087—It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEEPSS 2.1%