Weaknesses of type CWE-200

4,959 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-59427LOWCloudflare vite plugin exposes secrets over the built-in dev serverEPSS 0.4%CVE-2024-24755MEDIUMdiscourse-group-membership-ip-block is exposing potentially sensitive custom fieldsEPSS 0.4%CVE-2025-2842MEDIUMTempo-operator: tempo operator token exposition lead to read sensitive dataEPSS 0.4%CVE-2025-12010MEDIUMAuthors List <= 2.0.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Limited Method Call in Plugin's ShortcodeEPSS 0.4%CVE-2023-23499—This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS EPSS 0.4%CVE-2025-49150MEDIUMCursor Agent Potentially Leaks Information using JSON schemaEPSS 0.4%CVE-2026-72760MEDIUMcti-transmute Following List Exposes User Email Addresses to Authenticated UsersEPSS 0.4%CVE-2025-13596LOWImproper Error Handling Leading to Sensitive Information Disclosure in CIGES ≤ 2.15.6EPSS 0.4%CVE-2025-53003HIGHJanssen Config API returns results without scope verificationEPSS 0.4%CVE-2026-5266LOWExposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerability is associated wiEPSS 0.4%CVE-2026-54396MEDIUMMISP AuthKey edit endpoint allows authenticated user email enumerationEPSS 0.4%CVE-2026-94050MEDIUMD-Link DIR-X1860Z ubus JSON-RPC interface routerd.get_rand_key information disclosureEPSS 0.4%CVE-2025-23174HIGHYoel Geva - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.4%CVE-2024-21040MEDIUMVulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versioEPSS 0.4%CVE-2023-37232HIGHLoftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.EPSS 0.4%CVE-2026-32244MEDIUMDiscourse: Cached outdated summaries can leak removed contentEPSS 0.4%CVE-2026-28920MEDIUMAn information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26EPSS 0.4%CVE-2018-16883LOWsssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parEPSS 0.4%CVE-2026-54304HIGHn8n: SecurityScorecard Node Leaks API Token to User-Controlled HostEPSS 0.4%CVE-2015-8553MEDIUMXen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and IEPSS 0.4%