Weaknesses of type CWE-200

4,953 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-43998MEDIUMAn issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel accessEPSS 0.4%CVE-2024-23568MEDIUMHCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. DisplaEPSS 0.4%CVE-2026-4733MEDIUMInformation disclosure in ixray-1.6-stcopEPSS 0.4%CVE-2024-55946HIGHPlayloom Engine Data Storage VulnerabilityEPSS 0.4%CVE-2026-12203MEDIUMHKUDS AI-Trader Research Export agents.csv information disclosureEPSS 0.4%CVE-2025-52467CRITICALpgai secrets exfiltration via `pull_request_target`EPSS 0.4%CVE-2025-29745HIGHA vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTEPSS 0.4%CVE-2025-2883MEDIUMAccept SagePay Payments Using Contact Form 7 <= 2.0 - Unauthenticated Information ExposureEPSS 0.4%CVE-2026-59209HIGHn8n: Shared Credential Header Leak via HTTP Request Pagination ExpressionEPSS 0.4%CVE-2025-14197MEDIUMVerysync 微力同步 Web Administration f96956469e7be39d information disclosureEPSS 0.4%CVE-2024-41696HIGHPriority PRI WEB Portal Add-On for Priority ERP on prem – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.4%CVE-2025-2882MEDIUMGreenPay(tm) by Green.Money 3.0.0 - 3.0.9 - Unauthenticated Information ExposureEPSS 0.4%CVE-2026-77507MEDIUMWeblate: Object-scoped RSS feeds disclose private change history to unauthorized usersEPSS 0.4%CVE-2025-34072CRITICALAnthropic Slack MCP Server Data Exfiltration via Link UnfurlingEPSS 0.4%CVE-2025-45994HIGHAn issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST requesEPSS 0.4%CVE-2024-9530MEDIUMQi Addons For Elementor <= 1.8.0 - Sensitive Information ExposureEPSS 0.4%CVE-2026-72539MEDIUMWindmill Labs Windmill - Information DisclosureEPSS 0.4%CVE-2025-57430HIGHCreacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint reEPSS 0.4%CVE-2022-1353—A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged useEPSS 0.4%CVE-2026-67410HIGHRabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript EndpointEPSS 0.4%