Weaknesses of type CWE-200

4,898 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2021-31173MEDIUMMicrosoft SharePoint Server Information Disclosure VulnerabilityEPSS 2.1%CVE-2026-34474HIGHSensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web interEPSS 2.1%CVE-2020-24406LOWDocument root path disclosure on Maintenance pageEPSS 2.1%CVE-2025-50738CRITICALThe Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo contEPSS 2.1%CVE-2021-30168CRITICALMERIT LILIN ENT.CO.,LTD. P2/Z2/P3/Z3 IP camera - Sensitive Data Exposure-1EPSS 2.1%CVE-2021-44702LOWAdobe Acrobat Reader DC add-on (AxAcroPDFLib.AxAcroPDF) for Internet Explorer LoadFile NTLMv2 SSO Auth leak vulnerabilityEPSS 2.1%CVE-2021-44739LOWAdobe Acrobat Reader DC add-on (AxAcroPDFLib.AxAcroPDF) src NTLMv2 SSO Auth leak vulnerabilityEPSS 2.1%CVE-2023-36894MEDIUMMicrosoft SharePoint Server Information Disclosure VulnerabilityEPSS 2.1%CVE-2021-20228—A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature whenEPSS 2.1%CVE-2023-6266HIGHBackup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information ExposureEPSS 2.1%CVE-2022-29165CRITICALArgo CD will blindly trust JWT claims if anonymous access is enabledEPSS 2.1%CVE-2019-0202—The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versionEPSS 2.0%CVE-2026-33829MEDIUMWindows Snipping Tool Spoofing VulnerabilityEPSS 2.0%CVE-2024-1210MEDIUMLearnDash LMS <= 4.10.1 - Sensitive Information Exposure via APIEPSS 2.0%CVE-2017-6651—A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain information that could allow them to acEPSS 2.0%CVE-2023-40600MEDIUMWordPress EWWW Image Optimizer Plugin <= 7.2.0 is vulnerable to Sensitive Data ExposureEPSS 2.0%CVE-2021-21817HIGHAn information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially craftedEPSS 2.0%CVE-2023-29348HIGHWindows Remote Desktop Gateway (RD Gateway) Information Disclosure VulnerabilityEPSS 2.0%CVE-2023-40712—Apache Airflow: Secrets can be unmasked in the "Rendered Template" EPSS 2.0%CVE-2019-1908HIGHCisco Integrated Management Controller Information Disclosure VulnerabilityEPSS 2.0%