Weaknesses of type CWE-200

4,953 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-34072CRITICALAnthropic Slack MCP Server Data Exfiltration via Link UnfurlingEPSS 0.4%CVE-2025-10607MEDIUMPortabilis i-Educar diarioApi information disclosureEPSS 0.4%CVE-2021-32638MEDIUMCodeQL runner: Command-line options that make GitHub access tokens visible to other processes are now deprecatedEPSS 0.4%CVE-2024-6757MEDIUMElementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt FunctionEPSS 0.4%CVE-2026-27162MEDIUMDIscourse doesn't prevent whispers to leak in excerptsEPSS 0.4%CVE-2025-49593MEDIUMPortainer HTTP Headers May Leak to Malicious Container RegistriesEPSS 0.4%CVE-2024-9540MEDIUMSina Extension for Elementor <= 3.5.7 - Authenticated (Contributor+) Sensitive Information Exposure via Sina Modal Box Widget Elementor TemplateEPSS 0.4%CVE-2025-61907HIGHIcinga 2 API users could access restricted values in filter expressionsEPSS 0.4%CVE-2025-8519MEDIUMgivanz Vvveb Drag-and-Drop Editor editor information disclosureEPSS 0.4%CVE-2023-34250MEDIUMDiscourse vulnerable to exposure of number of topics recently created in private categoriesEPSS 0.4%CVE-2026-10055HIGHIn Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connecteEPSS 0.4%CVE-2025-37165HIGHExposure of VLAN information in unintended network interfacesEPSS 0.4%CVE-2026-63746HIGHSurrealDB before 3.1.0 Permission Bypass via Graph TraversalEPSS 0.4%CVE-2022-48516—Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerabilityEPSS 0.4%CVE-2026-8825MEDIUMElementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST APIEPSS 0.4%CVE-2026-50224MEDIUMUnauthenticated IPv6 WAN Management ExposureEPSS 0.4%CVE-2026-34091MEDIUMUser localization leaked by AbuseFilter + EventStreamEPSS 0.4%CVE-2026-34088LOWRecentChanges entries expose suppressed content via generated log page htmlEPSS 0.4%CVE-2023-42829MEDIUMThe issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7.9, macOS EPSS 0.4%CVE-2023-39383—Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromisEPSS 0.4%