Weaknesses of type CWE-200

4,959 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-22918HIGHPolycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator fEPSS 0.4%CVE-2024-48125HIGHAn issue in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate user credentials via crafted GIOP protocol reqEPSS 0.4%CVE-2026-73229MEDIUMDjango REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requestsEPSS 0.4%CVE-2025-25333HIGHAn issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link.EPSS 0.4%CVE-2024-6571MEDIUMOptimize Images ALT Text (alt tag) & names for SEO using AI <= 3.1.1 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-6548MEDIUMAdd Admin JavaScript <= 2.0 - Unauthenticated Full Path DislcosureEPSS 0.4%CVE-2024-6553MEDIUMWP Meteor Website Speed Optimization Addon <= 3.4.3 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2024-6545MEDIUMAdmin Trim Interface <= 3.5.1 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2025-55008HIGHAuthKit React Router: Sensitive auth data rendered in HTMLEPSS 0.4%CVE-2025-55009HIGHAuthKit: Sensitive auth data rendered in HTMLEPSS 0.4%CVE-2024-6559MEDIUMXCloner <= 4.7.3 - Unauthenticated Full Path DisclosureEPSS 0.4%CVE-2026-87017MEDIUMOpen WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backendsEPSS 0.4%CVE-2026-67339MEDIUMguzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header DisclosureEPSS 0.4%CVE-2025-11026MEDIUMgivanz Vvveb Configuration File information disclosureEPSS 0.4%CVE-2025-62699MEDIUMSpecial:Translate tool does not use the correct IP and User-Agent in the CheckUser toolEPSS 0.4%CVE-2025-26009HIGHTelesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.EPSS 0.4%CVE-2026-92933MEDIUMvm2 before 3.11.8 Information Disclosure via util.getCallSitesEPSS 0.4%CVE-2026-71293MEDIUMStatamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user VariableEPSS 0.4%CVE-2026-58027MEDIUMQueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UIEPSS 0.4%CVE-2026-16541MEDIUMSimply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST EndpointsEPSS 0.4%