Weaknesses of type CWE-200

4,953 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-28434MEDIUMcpp-httplib's default exception handler leaks e.what() to clients via EXCEPTION_WHAT response headerEPSS 0.4%CVE-2025-12276MEDIUMLearnHouse Image information disclosureEPSS 0.4%CVE-2024-3505MEDIUMJFrog Self-Hosted Artifactory Proxy configuration accessible to low-privilege usersEPSS 0.4%CVE-2026-90541MEDIUMWWBN AVideo Unauthenticated Information Disclosure via menus.json.phpEPSS 0.4%CVE-2026-53912MEDIUMCerebrate self-registration password hash exposure via inbox and audit log viewsEPSS 0.4%CVE-2026-57897MEDIUMCross-Repo Information Disclosure via Org-Level Actions Run/Job APIsEPSS 0.4%CVE-2026-9545HIGHexposing HTTP/3 early dataEPSS 0.4%CVE-2024-3228MEDIUMSocial Sharing Plugin – Kiwi <= 2.1.7 - Information DisclosureEPSS 0.4%CVE-2026-6346HIGHSensitive credentials exposed in plaintext in Mattermost support packetsEPSS 0.4%CVE-2026-27193HIGHFeathers exposes internal headers via unencrypted session cookieEPSS 0.4%CVE-2025-63209HIGHThe ELCA Star Transmitter Remote Control firmware 1.25 for STAR150, BP1000, STAR300, STAR2000, STAR1000, STAR500, and possibly other models,EPSS 0.4%CVE-2024-8899MEDIUMJeg Elementor Kit <= 2.6.9 - Authenticated (Contributor+) Sensitive Information Exposure via sg_content_templateEPSS 0.4%CVE-2026-54673HIGHelectron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`EPSS 0.4%CVE-2026-33677MEDIUMWebhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via APIEPSS 0.4%CVE-2026-76712HIGHUnauthenticated Remote Unauthorized Access, Information Disclosure, and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)EPSS 0.4%CVE-2023-47799HIGHMahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administratEPSS 0.4%CVE-2025-30214HIGHFrappe vulnerable to information disclosure leading to account takeoverEPSS 0.4%CVE-2022-41913MEDIUMDiscourse-calendar exposes members of hidden groupsEPSS 0.4%CVE-2026-42223MEDIUMnginx-ui: Settings API Exposes Protected SecretsEPSS 0.4%CVE-2026-30829MEDIUMCheckmate: Unauthenticated Access to Unpublished Status PageEPSS 0.4%