Weaknesses of type CWE-200

4,959 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-47124MEDIUMNezha WebSocket server stream discloses cross-tenant server telemetry to authenticated membersEPSS 0.4%CVE-2026-83116HIGHVulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions tEPSS 0.4%CVE-2022-45449HIGHSensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber PEPSS 0.4%CVE-2026-46427HIGHBudibase: Snowflake private key returned unmasked from datasource API to BASIC usersEPSS 0.4%CVE-2021-22783HIGHA CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. EPSS 0.4%CVE-2024-13042MEDIUMTsinghua Unigroup Electronic Archives Management System download.html download information disclosureEPSS 0.4%CVE-2026-16108MEDIUMKeycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2EPSS 0.4%CVE-2024-39919LOWCapture screenshot of localhost web services (unauthenticated pages) in @jmondi/url-to-pngEPSS 0.4%CVE-2026-58026NONE$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespacesEPSS 0.4%CVE-2026-46443HIGHFlowise: Credential Data LeakEPSS 0.4%CVE-2025-30352MEDIUMDirectus `search` query parameter allows enumeration of non permitted fieldsEPSS 0.4%CVE-2025-13785MEDIUMyungifez Skuul School Management System Image profile information disclosureEPSS 0.4%CVE-2025-62720HIGHLinkAce: Data Exfiltration via Export Functions Allow Access to All Users' Private LinksEPSS 0.4%CVE-2025-11997MEDIUMDocument Pro Elementor – Documentation & Knowledge Base <= 1.0.9 - Unauthenticated Information ExposureEPSS 0.4%CVE-2024-40554HIGHAn access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.EPSS 0.4%CVE-2025-22956CRITICALOPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalatEPSS 0.4%CVE-2026-85188MEDIUMJoomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for JoomlaEPSS 0.4%CVE-2026-58024MEDIUMAPI identification of users on private wikisEPSS 0.4%CVE-2025-9461MEDIUMdiyhi bbs File Compression FilePackageManageAction.java information disclosureEPSS 0.4%CVE-2025-43323HIGHThis issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS EPSS 0.4%