Weaknesses of type CWE-200

4,959 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-61917HIGHn8n Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task RunnerEPSS 0.4%CVE-2026-33886MEDIUMStatamic's sensitive configuration values are exposed to content editors via Antlers-enabled fieldsEPSS 0.4%CVE-2024-34991HIGHIn the module "Axepta" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credit card information (EPSS 0.4%CVE-2024-13498MEDIUMNEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2024-8913MEDIUMThe Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_templateEPSS 0.4%CVE-2025-10744MEDIUMFile Manager, Code editor, backup by Managefy <= 1.6.1 - Unauthenticated Information ExposureEPSS 0.4%CVE-2025-2331MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information ExposureEPSS 0.4%CVE-2017-15112—keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command histoEPSS 0.4%CVE-2026-84143CRITICALInternally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15EPSS 0.4%CVE-2023-41354MEDIUMChunghwa Telecom NOKIA G-040W-Q - Exposure of Sensitive InformationEPSS 0.4%CVE-2023-52101CRITICALComponent exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and inteEPSS 0.4%CVE-2024-8902MEDIUMElementor Addon Elements <= 1.13.8 - Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sectionsEPSS 0.4%CVE-2023-23629MEDIUMMetabase subject to Improper Privilege ManagementEPSS 0.4%CVE-2026-31262MEDIUMCross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive informatEPSS 0.4%CVE-2024-32037NONEGeoNetwork vulnerable to search end-point information disclosure in response headersEPSS 0.4%CVE-2023-5515MEDIUM The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal sEPSS 0.4%CVE-2025-46552MEDIUMKHC-INVITATION-AUTOMATION Sensitive User Information Leakage in Invitation AutomationEPSS 0.4%CVE-2024-40633MEDIUMCustomer data leak via adjustments API endpoint in SyliusEPSS 0.4%CVE-2026-87076MEDIUMTanium addressed an information disclosure vulnerability in Discover.EPSS 0.4%CVE-2023-28900MEDIUMNickname Disclosure on the Backend Automotive ServerEPSS 0.4%