Weaknesses of type CWE-200

4,953 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-73308MEDIUMBudibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other BuildersEPSS 0.4%CVE-2025-12558MEDIUMBeaver Builder – WordPress Page Builder <= 2.9.4 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%CVE-2022-22447MEDIUMIBM Disconnected Log Collector information disclosureEPSS 0.4%CVE-2024-26312MEDIUMArcher Platform 6 before 2024.03 contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtaEPSS 0.4%CVE-2024-5813MEDIUMSSH Private Key Leak in BeyondInsight PasswordSafeEPSS 0.4%CVE-2026-30847CRITICALWekan Credential Leak via notificationUsers Publication Exposes Password Hashes and Session TokensEPSS 0.4%CVE-2026-61783HIGHWazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to read cluster.keyEPSS 0.4%CVE-2022-3611HIGHAn information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized aEPSS 0.4%CVE-2025-36601MEDIUMDell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerabiliEPSS 0.4%CVE-2022-46310HIGHThe TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentEPSS 0.4%CVE-2026-34518LOWAIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirectEPSS 0.4%CVE-2024-40597HIGHAn issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The lEPSS 0.4%CVE-2025-60949CRITICALCensus CSWeb leaked configuration filesEPSS 0.4%CVE-2022-30736MEDIUMImproper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery wiEPSS 0.4%CVE-2025-58059CRITICALValtimo scripting engine can be used to gain access to sensitive data or resourcesEPSS 0.4%CVE-2026-68520MEDIUMGlances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/configEPSS 0.4%CVE-2025-22960HIGHA session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters. Unauthenticated aEPSS 0.4%CVE-2022-30743MEDIUMImproper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery wiEPSS 0.4%CVE-2025-46813MEDIUMPrivate data leak on login-required Discourse sitesEPSS 0.4%CVE-2024-29885MEDIUMReports are still accessible even when `canView()` returns false in silverstripe/reportsEPSS 0.4%