Weaknesses of type CWE-200

4,958 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-28235HIGHAn information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.EPSS 0.4%CVE-2024-38749MEDIUMWordPress Olive One Click Demo Import plugin <= 1.1.2 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-25523MEDIUMMagento's X-Original-Url header can expose admin urlEPSS 0.4%CVE-2024-23493MEDIUM Team associated AD/LDAP Groups Leaked due to missing authorizationEPSS 0.4%CVE-2026-8993MEDIUMImproper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacksEPSS 0.4%CVE-2025-9774MEDIUMRemoteClinic edit-patient.php information disclosureEPSS 0.4%CVE-2022-24886LOWExposure of Sensitive Information to an Unauthorized Actor in com.nextcloud.clientEPSS 0.4%CVE-2026-27481MEDIUMDiscourse: Hidden tag visibility bypass on tag routesEPSS 0.4%CVE-2026-62473HIGHVulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that arEPSS 0.4%CVE-2026-19992LOWOrange View Limited DualSafe Password Manager & Digital Vault Extension postMessage-based Bridge information disclosureEPSS 0.4%CVE-2025-13683MEDIUMExposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions ServeEPSS 0.4%CVE-2026-6756HIGHMitigation bypass in Firefox for AndroidEPSS 0.4%CVE-2017-12361—A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to access sensitive communications made by the JaEPSS 0.4%CVE-2025-20336MEDIUMCisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Firmware Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-58511LOWWebhook Authorization Header Returned in Plaintext via APIEPSS 0.4%CVE-2024-26132MEDIUMElement Android can be asked to share internal files.EPSS 0.4%CVE-2026-7382MEDIUMInformation Disclosure in MeWare Software's PDKSEPSS 0.4%CVE-2025-2252MEDIUMEasy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title DisclosureEPSS 0.4%CVE-2026-34948HIGHCombodo iTop: Access control bypass via OQL joinsEPSS 0.4%CVE-2026-27892MEDIUMFacturaScripts: Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/DownloadEPSS 0.4%