Weaknesses of type CWE-200

4,958 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-43996MEDIUMAn issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access tokEPSS 0.4%CVE-2026-47389HIGHMastodon: SSRF protection bypass on older Ruby versionsEPSS 0.4%CVE-2026-35452MEDIUMWWBN AVideo has Unauthenticated Information Disclosure via Missing Auth on CloneSite client.log.phpEPSS 0.4%CVE-2026-3131MEDIUMImproper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user witEPSS 0.4%CVE-2026-78474MEDIUMNi WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and Customer Data Disclosure via 'btn_print' ParameterEPSS 0.4%CVE-2022-48514—The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confEPSS 0.4%CVE-2026-66272MEDIUMDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unautEPSS 0.4%CVE-2023-43993MEDIUMAn issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel EPSS 0.4%CVE-2026-69189HIGHHoppscotch: Cross-user private data exposure and UserHistory IDOR via team GraphQL resolversEPSS 0.4%CVE-2024-7319MEDIUMOpenstack-heat: incomplete fix for cve-2023-1625EPSS 0.4%CVE-2025-52493MEDIUMPagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets apEPSS 0.4%CVE-2026-92357MEDIUMa2ui-project a2ui Model Processor model-processor.ts information disclosureEPSS 0.4%CVE-2026-76390MEDIUMInformation Disclosure through Splunk Web in Cisco Talos Intelligence for Enterprise Security CloudEPSS 0.4%CVE-2026-66018MEDIUMJFrog Artifactory build environment properties exposureEPSS 0.4%CVE-2026-61251MEDIUMVulnerability in the HRMS (Australia) product of Oracle E-Business Suite (component: Payroll). Supported versions that are affected are 12.EPSS 0.4%CVE-2026-34313MEDIUMVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.4%CVE-2026-34300MEDIUMVulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that iEPSS 0.4%CVE-2026-60609MEDIUMVulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Communication). The supported versEPSS 0.4%CVE-2024-36986MEDIUMRisky command safeguards bypass through Search ID query in Analytics WorkspaceEPSS 0.4%CVE-2025-31225HIGHA privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS 18.5. Call history from deleted apps maEPSS 0.4%