Weaknesses of type CWE-200

4,958 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-31494LOWAutoGPT allows cross-user sharing of node execution results through WebSockets APIEPSS 0.4%CVE-2026-72834MEDIUMfilebrowser before 2.63.19 Permission Bypass via checksumEPSS 0.4%CVE-2026-45351MEDIUMOpen WebUI: Exposure of System Prompt to Regular User [Non-Admin]EPSS 0.4%CVE-2026-21626CRITICALExtension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss 1.0.0-5.0.15 for JoomlaEPSS 0.4%CVE-2022-34351MEDIUMIBM QRadar SIEM information disclosureEPSS 0.4%CVE-2022-42843HIGHThis issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watcEPSS 0.4%CVE-2025-26309MEDIUMA memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, which allows attackerEPSS 0.4%CVE-2025-26310MEDIUMMultiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE) in util/parser.c ofEPSS 0.4%CVE-2026-1556MEDIUMInformation disclosure via file URI overwrite in File (Field) PathsEPSS 0.4%CVE-2025-26167HIGHBuffalo LS520D 4.53 is vulnerable to Arbitrary file read, which allows unauthenticated attackers to access the NAS web UI and read arbitraryEPSS 0.4%CVE-2026-54264HIGHAngular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service WorkerEPSS 0.4%CVE-2025-0659HIGHPath Traversal and Rockwell Automation Third-party Vulnerability in DataMosaix™ Private CloudEPSS 0.4%CVE-2026-33220MEDIUMWeblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryEPSS 0.4%CVE-2025-2881MEDIUMDeveloper Toolbar <= 1.0.3 - Unauthenticated Information ExposureEPSS 0.4%CVE-2026-56882HIGHIn Cellular Modem, there is a possible information disclosure due to a logic error in the code. This could lead to remote code execution witEPSS 0.4%CVE-2026-56235MEDIUMCapgo - Unauthenticated Cross-Tenant Metrics Disclosure via RPC FunctionsEPSS 0.4%CVE-2025-2880MEDIUMYame | Link In Bio <= 0.9.0 - Unauthenticated Information ExposureEPSS 0.4%CVE-2025-28235HIGHAn information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.EPSS 0.4%CVE-2026-8993MEDIUMImproper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacksEPSS 0.4%CVE-2024-23493MEDIUM Team associated AD/LDAP Groups Leaked due to missing authorizationEPSS 0.4%