Weaknesses of type CWE-200

4,959 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2020-1698MEDIUMA flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. EPSS 0.4%CVE-2026-83437HIGHVulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported versions that are affeEPSS 0.4%CVE-2025-3403MEDIUMVivotek NVR ND8422P/NVR ND9525P/NVR ND9541P HTML Form sensitive information in sourceEPSS 0.4%CVE-2026-14928MEDIUMJS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubjectEPSS 0.4%CVE-2026-47124MEDIUMNezha WebSocket server stream discloses cross-tenant server telemetry to authenticated membersEPSS 0.4%CVE-2026-18943MEDIUMWPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta DisclosureEPSS 0.4%CVE-2026-12976MEDIUMLearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI AssistantEPSS 0.4%CVE-2026-16541MEDIUMSimply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST EndpointsEPSS 0.4%CVE-2026-58027MEDIUMQueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UIEPSS 0.4%CVE-2026-83287HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). SupporEPSS 0.4%CVE-2026-16968MEDIUMGeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_usersEPSS 0.4%CVE-2026-83116HIGHVulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions tEPSS 0.4%CVE-2020-7284HIGHNetwork Security Management (NSM) - Exposure of Sensitive InformationEPSS 0.4%CVE-2026-83443MEDIUMVulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecteEPSS 0.4%CVE-2026-19613MEDIUMECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF SourceEPSS 0.4%CVE-2026-16562MEDIUMWP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX HandlersEPSS 0.4%CVE-2026-13168MEDIUMEventin < 4.1.20 - Contributor+ Customer PII Disclosure via REST APIEPSS 0.4%CVE-2026-42092MEDIUMGlobal Settings Publication Exposes Sensitive Configuration to Any Authenticated User in TitraEPSS 0.4%CVE-2026-46427HIGHBudibase: Snowflake private key returned unmasked from datasource API to BASIC usersEPSS 0.4%CVE-2026-16590MEDIUMWP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data DisclosureEPSS 0.4%