Weaknesses of type CWE-200

4,951 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-45553HIGHNiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()EPSS 0.4%CVE-2026-56226HIGHCapgo - Unauthenticated Organization Data Disclosure via get_orgs_v6 RPCEPSS 0.4%CVE-2026-72804CRITICALSiYuan before v3.7.4 Authentication Bypass via Graph EndpointsEPSS 0.4%CVE-2026-88893HIGHOpenPanel Unauthenticated Share Lookup Information DisclosureEPSS 0.4%CVE-2026-91985HIGHVikunja before 2.6.0 Privilege Escalation via Link Share HashEPSS 0.4%CVE-2026-41032HIGHPhoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllersEPSS 0.4%CVE-2025-7919HIGHSimopro Technology|WinMatrix3 Web package - SQL InjectionEPSS 0.4%CVE-2024-13568HIGHFluent Support – Helpdesk & Customer Support Ticket System <= 1.8.5 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.4%CVE-2026-73178HIGHApache Syncope: JWT Access Token takeoverEPSS 0.4%CVE-2026-81270HIGHApache Allura: Information exposure via searchEPSS 0.4%CVE-2024-6574MEDIUMLaposta <= 1.12 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-13606HIGHJS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.8 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.4%CVE-2024-4837MEDIUMTrust Boundary Violation VulnerabilityEPSS 0.4%CVE-2026-5336MEDIUMDataverse Integration < 2.91 - Contributor+ Server-Side Template Injection (SSTI) to Information DisclosureEPSS 0.4%CVE-2026-47735HIGHArc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checksEPSS 0.4%CVE-2026-48767HIGHGoogle Sheets OAuth access token disclosure to guest members via getAccessTokenEPSS 0.4%CVE-2026-7626MEDIUMSlek Gateway for WooCommerce <= 1.0 - Unauthenticated Insufficiently Protected Credentials via Payment Redirect Form Hidden FieldsEPSS 0.4%CVE-2026-14611MEDIUMDeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of resourceEPSS 0.4%CVE-2024-10357MEDIUMClever Addons for Elementor <= 2.2.1 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesEPSS 0.4%CVE-2026-24498MEDIUMExposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX200EPSS 0.4%