Weaknesses of type CWE-200

4,952 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-53036HIGHVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.4%CVE-2024-5059MEDIUMWordPress Event Monster Plugin <= 1.4.0 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2023-28357MEDIUMA vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is aEPSS 0.4%CVE-2026-7544MEDIUMMux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information ExposureEPSS 0.4%CVE-2026-4126MEDIUMTable Manager <= 1.0.0 - Authenticated (Contributor+) Sensitive Information Exposure via 'table' Shortcode AttributeEPSS 0.4%CVE-2026-12385MEDIUMSmart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' ParameterEPSS 0.4%CVE-2011-4916—Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.EPSS 0.4%CVE-2026-3691MEDIUMOpenClaw Client PKCE Verifier Information Disclosure VulnerabilityEPSS 0.4%CVE-2022-31746MEDIUMInternal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability aEPSS 0.4%CVE-2026-42151HIGHPrometheus Azure AD remote write OAuth client secret exposed via config APIEPSS 0.4%CVE-2026-7526MEDIUMPDF Embedder <= 4.9.3 - Authenticated (Contributor+) Information Exposure via Block Editor PageEPSS 0.4%CVE-2025-32983HIGHNETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.EPSS 0.4%CVE-2025-68279HIGHWeblate has an arbitrary file read via symbolic linksEPSS 0.4%CVE-2026-73604HIGHFlowise before 3.1.3 Credential Exposure via APIEPSS 0.4%CVE-2026-32237MEDIUM@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpointEPSS 0.4%CVE-2026-35038LOWsignalk-server: Arbitrary Prototype Read via `from` Field BypassEPSS 0.4%CVE-2026-44231CRITICALRT: Privilege escalation and information disclosure via REST 2.0 user collection endpointEPSS 0.4%CVE-2023-41749MEDIUMSensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (WindEPSS 0.4%CVE-2026-67529MEDIUMOpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)EPSS 0.4%CVE-2026-19837MEDIUMWebkul Bagisto Customer Search search information disclosureEPSS 0.4%