Weaknesses of type CWE-200

4,959 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2015-7946HIGHMTP service exposed during emergency dialerEPSS 0.4%CVE-2024-12159MEDIUMOptimize Your Campaigns – Google Shopping – Google Ads – Google Adwords <= 3.1 - Information ExposureEPSS 0.4%CVE-2025-40940MEDIUMA vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits inconsistent SNMP behaviorEPSS 0.4%CVE-2026-28922MEDIUMThis issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26EPSS 0.4%CVE-2024-36122LOWDiscourse doesn't limit reviewable user serializer payloadEPSS 0.4%CVE-2026-55180MEDIUMpnpm: Repository config can expand victim environment secrets into registry requests before scripts runEPSS 0.4%CVE-2025-62721HIGHLinkAce: Authorization Bypass Allows Unauthorized Access to All Private Links, Lists, and TagsEPSS 0.4%CVE-2022-32540HIGHInformation Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30EPSS 0.4%CVE-2025-1714MEDIUMUsername Enumeration in GliffyEPSS 0.4%CVE-2021-37190MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information discEPSS 0.4%CVE-2021-37192MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information discEPSS 0.4%CVE-2025-13765MEDIUMExposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: beEPSS 0.4%CVE-2024-35710MEDIUMWordPress Podlove Web Player plugin <= 5.7.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-53245LOWInformation Disclosure due to Username Collision with a Role that has the same Name as the UserEPSS 0.4%CVE-2026-2207MEDIUMWeKan Activity Publication activities.js LinkedBoardActivitiesBleed information disclosureEPSS 0.4%CVE-2024-47344MEDIUMWordPress uListing plugin <= 2.1.5 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-37924MEDIUMWordPress WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin <= 1.0.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2020-15704MEDIUMpppd arbitrary file read information disclosure vulnerabilityEPSS 0.4%CVE-2024-9627HIGHTeploBot - Telegram Bot for WP <= 1.3 - Telegram Bot Token DisclosureEPSS 0.4%CVE-2024-38760MEDIUMWordPress Send Users Email plugin <= 1.5.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%