Weaknesses of type CWE-200

4,951 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-47176MEDIUMQuest Bot: Logging module can disclose private-channel message contents to a lower-visibility log channelEPSS 0.4%CVE-2026-53725MEDIUMParse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is deniedEPSS 0.4%CVE-2024-27113CRITICALInsecure Direct Object Reference to export Database in SOPlanning before 1.52.02EPSS 0.4%CVE-2026-47177MEDIUMQuest Bot: Ticket transcripts can disclose private ticket contents to a lower-visibility channelEPSS 0.4%CVE-2026-8965HIGHInformation disclosure in the DOM: Security componentEPSS 0.4%CVE-2026-6347HIGHMattermost Calls plugin exposes TURN server credentials in plaintext in support packetsEPSS 0.4%CVE-2023-30611MEDIUMReaction metadata exposed in private topics in Discourse-reactionsEPSS 0.4%CVE-2026-8966HIGHInformation disclosure in the IP Protection componentEPSS 0.4%CVE-2026-8967HIGHInformation disclosure in the Graphics: WebGPU componentEPSS 0.4%CVE-2024-43707HIGHKibana exposure of sensitive information to an unauthorized actorEPSS 0.4%CVE-2026-6782HIGHInformation disclosure in the IP Protection componentEPSS 0.4%CVE-2023-31416MEDIUMElastic Cloud on Kubernetes (ECK) secret token configuration issueEPSS 0.4%CVE-2026-60415HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.4%CVE-2023-50894HIGHIn Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.PasswordEncryption password EPSS 0.4%CVE-2026-17048MEDIUMKeycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest apiEPSS 0.4%CVE-2025-62604MEDIUMMeterSphere logic flaw allows retrieval of arbitrary user informationEPSS 0.4%CVE-2026-67357HIGHArcadeDB before 26.7.3 Information Disclosure via get_server_settingsEPSS 0.4%CVE-2025-13371HIGHMoney Space <= 2.13.9 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2026-50870HIGHAn information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitivEPSS 0.4%CVE-2024-6549MEDIUMAdmin Post Navigation <= 2.1 - Unauthenticated Full Path DisclosureEPSS 0.4%