Weaknesses of type CWE-200

4,958 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-56282MEDIUMCapgo - Information Disclosure via Unauthenticated /replication EndpointEPSS 0.4%CVE-2024-35341HIGHCertain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET request to /ConfigFilEPSS 0.4%CVE-2024-47923MEDIUMMashov – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.4%CVE-2024-32131MEDIUMWordPress Download Manager plugin <= 3.2.82 - File Password Lock Bypass vulnerabilityEPSS 0.4%CVE-2026-71085MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-62559MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.4%CVE-2024-6455MEDIUMElementsKit Elementor addons <= 3.2.0 - Unauthenticated Information Exposure via ekit_widgetarea_content FunctionEPSS 0.4%CVE-2026-90548MEDIUMWWBN AVideo Missing Authorization in ImageGallery list.json.phpEPSS 0.4%CVE-2025-3923MEDIUMPrevent Direct Access – Protect WordPress Files <= 2.8.8 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2025-23203MEDIUMIcinga has rest API endpoints accessible to restricted usersEPSS 0.4%CVE-2026-21940HIGHVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported version that is affecEPSS 0.4%CVE-2025-22961HIGHA critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters due EPSS 0.4%CVE-2023-27317MEDIUMInformation Disclosure Vulnerability in ONTAP 9 EPSS 0.4%CVE-2026-53497MEDIUMCrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active session metadata (IP, User-Agent, session IDs)EPSS 0.4%CVE-2026-13230MEDIUMInformation Disclosure Vulnerability in Local Discovery Response in TP-Link Kasa EC70 and EC71EPSS 0.4%CVE-2026-49462MEDIUMnl.nl-portal:app has GraphiQL UI and GraphQL schema introspection enabled by defaultEPSS 0.4%CVE-2025-50074MEDIUMVulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: EPSS 0.4%CVE-2024-2080MEDIUMLiquidPoll – Polls, Surveys, NPS and Feedback Reviews <= 3.3.76 - Information ExposureEPSS 0.4%CVE-2026-50697HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-41893MEDIUMAccount takeover via auth_callback login in Home Assistant CoreEPSS 0.4%