Weaknesses of type CWE-200

4,951 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-19717HIGHCatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST APIEPSS 0.4%CVE-2026-16988HIGHGeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST EndpointEPSS 0.4%CVE-2026-15048HIGHGeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat HistoryEPSS 0.4%CVE-2026-15236HIGHGallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token DisclosureEPSS 0.4%CVE-2026-18470HIGHLogin & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password ResponseEPSS 0.4%CVE-2026-16604HIGHContent Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content AttributeEPSS 0.4%CVE-2026-16602HIGHContent Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure via Captcha REST EndpointEPSS 0.4%CVE-2026-18049HIGHWP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogoEPSS 0.4%CVE-2026-16253HIGHTotal Upkeep < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secretEPSS 0.4%CVE-2024-8553MEDIUMForeman: read-only access to entire db from templatesEPSS 0.4%CVE-2026-58432MEDIUMMissing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/giteaEPSS 0.4%CVE-2025-8525MEDIUMExrick xboot Spring Boot Admin/Spring Actuator information disclosureEPSS 0.4%CVE-2026-27611HIGHFileBrowser Quantum: Password Protection Not Enforced on Shared File LinksEPSS 0.4%CVE-2026-56259HIGHCrawl4AI - LLM Credential Exfiltration via base_url and Environment Variable ResolutionEPSS 0.4%CVE-2025-59184MEDIUMStorage Spaces Direct Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-59188MEDIUMMicrosoft Failover Cluster Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-41230HIGHVMware Cloud Foundation Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-1477MEDIUMEasy Maintenance Mode <= 1.4.2 - Information ExposureEPSS 0.4%CVE-2026-41032HIGHPhoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllersEPSS 0.4%CVE-2026-88893HIGHOpenPanel Unauthenticated Share Lookup Information DisclosureEPSS 0.4%