Weaknesses of type CWE-200

4,959 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-87076MEDIUMTanium addressed an information disclosure vulnerability in Discover.EPSS 0.4%CVE-2026-31262MEDIUMCross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive informatEPSS 0.4%CVE-2026-56729LOWZammad: Titles of knowledge base answers will be shown across all categories via the global searchEPSS 0.4%CVE-2025-27604HIGHXWiki Confluence Migrator Pro's homepage is publicEPSS 0.4%CVE-2025-26001HIGHTelesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.EPSS 0.4%CVE-2019-5641LOWRapid7 InsightVM Information Disclosure after LogoutEPSS 0.4%CVE-2025-54380MEDIUMOpencast still publishes global system account credentialsEPSS 0.4%CVE-2024-31464MEDIUMXWiki Platform: Password hash might be leaked by diff once the xobject holding them is deletedEPSS 0.4%CVE-2024-11008MEDIUMMembers <= 3.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.4%CVE-2026-60647HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions tEPSS 0.4%CVE-2023-38245MEDIUMAdobe Acrobat Reader DC ActiveX Control (AxAcroPDFLib.AxAcroPDF) src NTLMv2 SSO Hash Theft VulnerabilityEPSS 0.4%CVE-2024-13807HIGHXagio SEO <= 7.1.0.5 - Unauthenticated Sensitive Information Exposure via Unprotected Back-Up FilesEPSS 0.4%CVE-2023-31280MEDIUMExposure of Sensitive Information to an Unauthorized ActorEPSS 0.4%CVE-2024-33753HIGHSection Camera V2.5.5.3116-S50-SMA-B20160811 and earlier versions allow the accounts and passwords of administrators and users to be changedEPSS 0.4%CVE-2025-0525LOWIn affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could EPSS 0.4%CVE-2023-21833MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is aEPSS 0.4%CVE-2025-5184MEDIUMSummer Pearl Group Vacation Rental Management Platform HTTP Response Header information disclosureEPSS 0.4%CVE-2024-10360MEDIUMMove Addons for Elementor <= 1.3.5 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesEPSS 0.4%CVE-2024-20937MEDIUMVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC). Supported verEPSS 0.4%CVE-2025-14464MEDIUMPDF Resume Parser <= 1.0 - Unauthenticated Sensitive Information Disclosure in SMTP CredentialsEPSS 0.4%