Weaknesses of type CWE-200

4,951 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-78174CRITICALWatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic LogsEPSS 0.4%CVE-2025-59535MEDIUMDotNetNuke.Core allows loading of unused themes on anonymous clients through query parametersEPSS 0.4%CVE-2026-60031MEDIUMJoomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1EPSS 0.4%CVE-2026-47379MEDIUMNocoDB: Plaintext Password Comparison in Shared ViewsEPSS 0.4%CVE-2024-41259CRITICALUse of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account informationEPSS 0.4%CVE-2025-30127CRITICALAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, thEPSS 0.4%CVE-2024-28339MEDIUMAn information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attaEPSS 0.4%CVE-2025-30724HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.EPSS 0.4%CVE-2023-34442—Apache Camel JIRA: Temporary file information disclosure in Camel-JiraEPSS 0.4%CVE-2024-45040MEDIUMgnark's commitments to private witnesses in Groth16 as implemented break zero-knowledge propertyEPSS 0.4%CVE-2026-73082MEDIUMActivepieces: Server-side request forgery in MCP tool validation endpointEPSS 0.4%CVE-2026-77132MEDIUMTYPO3 CMS - Information Disclosure via Backend Localization WizardEPSS 0.4%CVE-2020-10750HIGHSensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store EPSS 0.4%CVE-2026-85055HIGHTwenty: Field-level read bypassEPSS 0.4%CVE-2025-32986HIGHNETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.EPSS 0.4%CVE-2026-59503CRITICALPriority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.4%CVE-2022-27891MEDIUMPalantir Gotham included an unauthenticated endpoint that listed all active usernames in the platform with an active session. EPSS 0.4%CVE-2022-0850—A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.EPSS 0.4%CVE-2026-1170MEDIUMbirkir prime GraphQL API graphql information disclosureEPSS 0.4%CVE-2025-68110CRITICALChurchCRM discloses database information on error messageEPSS 0.4%