Weaknesses of type CWE-200

4,959 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-39857MEDIUMInformation Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field RestrictionsEPSS 0.4%CVE-2024-13546MEDIUMGenerateBlocks <= 1.9.1 - Authenticated (Contributor+) Sensitive Information Exposure via 'get_image_description'EPSS 0.4%CVE-2025-25468MEDIUMFFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.EPSS 0.4%CVE-2015-8553MEDIUMXen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and IEPSS 0.4%CVE-2025-25942MEDIUMAn issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files.EPSS 0.4%CVE-2024-34897HIGHNedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.EPSS 0.4%CVE-2025-25729HIGHAn information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allowsEPSS 0.4%CVE-2026-62986MEDIUMOpenEXR: PyOpenEXR deep prefixed RGB stale lane disclosureEPSS 0.4%CVE-2026-79776MEDIUMrclone before 1.75.0 Authentication Bypass via pprofEPSS 0.4%CVE-2025-25945MEDIUMAn issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CEPSS 0.4%CVE-2026-84136CRITICALOther issue in the DOM: Navigation componentEPSS 0.4%CVE-2024-38467HIGHShenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.EPSS 0.4%CVE-2024-47915HIGHVaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.4%CVE-2025-61917HIGHn8n Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task RunnerEPSS 0.4%CVE-2024-13498MEDIUMNEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2026-8405MEDIUMIBM Guardium Data Protection is affected by Exposure of Sensitive Information vulnerabilityEPSS 0.4%CVE-2026-56839HIGHPraisonAI Code agent tools fail open without a workspace boundaryEPSS 0.4%CVE-2026-30891MEDIUMDiscourse hasUnauthorized Exposure of Private User Action TypesEPSS 0.4%CVE-2025-51040HIGHElectrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the /FrameSetCore.html endpoint in ElectrolinkEPSS 0.4%CVE-2024-34991HIGHIn the module "Axepta" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credit card information (EPSS 0.4%