Weaknesses of type CWE-200

4,952 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-33353HIGHSoft Serve: Authenticated repo import can clone server-local private repositoriesEPSS 0.4%CVE-2024-6687MEDIUMCTT Expresso para WooCommerce <= 3.2.12 - Information Exposure via Unprotected DirectoryEPSS 0.4%CVE-2023-46254MEDIUMService accounts can see namespaces of other tenants in capsule-proxyEPSS 0.4%CVE-2026-26964LOWWindmill Exposes Workspace Slack OAuth Client Secrets to Non-Admin Workspace MembersEPSS 0.4%CVE-2025-15121MEDIUMJeecgBoot getDeptRoleByUserId information disclosureEPSS 0.4%CVE-2026-47351MEDIUMTYPO3 CMS - Broken Access Control in ClipboardEPSS 0.4%CVE-2026-3058MEDIUMSeraphinite Accelerator <= 2.28.14 - Authenticated (Subscriber+) Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.4%CVE-2024-7417MEDIUMRoyal Elementor Addons and Templates <= 1.3.986 - Authenticated (Subscriber+) Private Post DisclosureEPSS 0.4%CVE-2026-48499CRITICALActivepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cacheEPSS 0.4%CVE-2024-10329MEDIUMUltimate Bootstrap Elements for Elementor <= 1.4.6 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%CVE-2026-32625CRITICALLibreChat Exfiltrates Server Secrets via MCP Server URL InjectionEPSS 0.4%CVE-2026-24422MEDIUMphpMyFAQ: Public API endpoints expose emails and invisible questionsEPSS 0.4%CVE-2024-8801MEDIUMHappy Addons for Elementor <= 3.12.2 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%CVE-2023-29111LOWInformation Disclosure vulnerability in SAP Application Interface Framework (ODATA service)EPSS 0.4%CVE-2026-58033MEDIUM"Total number of distinct authors" statistic at action=info does not exclude revisions where the author name was deletedEPSS 0.4%CVE-2026-28675MEDIUMOpenSift: Sensitive implementation details exposed via raw exception messages and token-returning endpointsEPSS 0.4%CVE-2024-32963MEDIUMParameter Tampering vulnerability in NavidromeEPSS 0.4%CVE-2025-8091MEDIUMEventON Lite <= 2.4.7 - Authenticated (Contributor+) Information DisclosureEPSS 0.4%CVE-2018-0335—A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attEPSS 0.4%CVE-2024-5059MEDIUMWordPress Event Monster Plugin <= 1.4.0 - Sensitive Data Exposure vulnerabilityEPSS 0.4%