Weaknesses of type CWE-200

4,951 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-35442HIGHDirectus: Authenticated Users Can Extract Concealed Fields via Aggregate QueriesEPSS 0.4%CVE-2026-48766HIGHTypeBot vulnerable to OpenAI API key exfiltration in listModels via attacker-controlled baseUrlEPSS 0.4%CVE-2026-79776MEDIUMrclone before 1.75.0 Authentication Bypass via pprofEPSS 0.4%CVE-2026-77017HIGHWorkeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Read via Candidate Profile Mass AssignmentEPSS 0.4%CVE-2025-52898HIGHFrappe account takeover via password reset token leakageEPSS 0.4%CVE-2025-49177MEDIUMXorg-x11-server-xwayland: xorg-x11-server: tigervnc: data leak in xfixes extension's xfixessetclientdisconnectmodeEPSS 0.4%CVE-2026-41278HIGHFlowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDsEPSS 0.4%CVE-2024-10356MEDIUMElementsReady Addons for Elementor <= 6.4.8 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesEPSS 0.4%CVE-2026-16954MEDIUMAI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer TokensEPSS 0.4%CVE-2024-22301MEDIUMWordPress Albo Pretorio Online Plugin <= 4.6.6 is vulnerable to Sensitive Data ExposureEPSS 0.4%CVE-2026-78174CRITICALWatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic LogsEPSS 0.4%CVE-2026-42564HIGHjotty·page: Unauthenticated Path Traversal leads to sensitive file disclosure and session-token reuse impactEPSS 0.4%CVE-2026-47193HIGHOpenProject: Journal diff endpoint bypasses object, journal, and field visibility checksEPSS 0.4%CVE-2025-27845CRITICALIn ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secretEPSS 0.4%CVE-2025-54118MEDIUMNamelessMC allows sensitive information disclosure in member list componentEPSS 0.4%CVE-2026-77246HIGHMCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload PathEPSS 0.4%CVE-2022-20953MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software VulnerabilitiesEPSS 0.4%CVE-2026-42871MEDIUMWeGIA: Error Handling familiar_docfamiliarEPSS 0.4%CVE-2026-44206MEDIUMFrappe: DB Schema Enumeration via Frappe-Authorization-SourceEPSS 0.4%CVE-2025-14280MEDIUMPixelYourSite <= 11.1.5 - Sensitive Information Exposure via Log FileEPSS 0.4%