Weaknesses of type CWE-200

4,952 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-32789LOWEspoCRM Allows Potential Disclosure of Sensitive Information in the User Sorting FunctionEPSS 0.4%CVE-2025-47417MEDIUMEnable Debug ImagesEPSS 0.4%CVE-2024-6336MEDIUMSecurity misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposureEPSS 0.4%CVE-2026-44786HIGHDiscourse: Public chat MessageBus broadcasts are not restricted to chat-eligible usersEPSS 0.4%CVE-2026-7041MEDIUM666ghj MiroFish Werkzeug Debugger PIN console information disclosureEPSS 0.4%CVE-2025-43449HIGHThe issue was addressed with improved handling of caches. This issue is fixed in iOS 26.1 and iPadOS 26.1. A malicious app may be able to trEPSS 0.4%CVE-2026-87225HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-76706MEDIUMUnauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API allows exposure of sensitive dataEPSS 0.4%CVE-2025-15625CRITICALUnauthenticated execution of arbitrary SQL queries in Sparx Pro Cloud ServerEPSS 0.4%CVE-2023-1831HIGHUser password logged in audit logsEPSS 0.4%CVE-2025-67274HIGHAn issue in continuous.software aangine v.2025.2 allows a remote attacker to obtain sensitive information via the excel-integration-service EPSS 0.4%CVE-2024-37150HIGHPrivate npm registry support used scope auth token for downloading tarballsEPSS 0.4%CVE-2026-87209HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-44979MEDIUM@hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-hostname redirectsEPSS 0.4%CVE-2026-60176HIGHVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 0.4%CVE-2026-9583MEDIUMSourceCodester CET Automated Grading System with AI Predictive Analytics SQL index.php information exposureEPSS 0.4%CVE-2026-76717MEDIUMUnauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.4%CVE-2023-3349HIGHInformation exposure on IBERMATICA RPSEPSS 0.4%CVE-2026-17457MEDIUMmf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosureEPSS 0.4%CVE-2026-15329MEDIUMzhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate information disclosureEPSS 0.4%