Weaknesses of type CWE-200

4,959 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-33041MEDIUMAVideo has an Unauthenticated Password Hash Oracle via encryptPass.json.phpEPSS 0.4%CVE-2026-2207MEDIUMWeKan Activity Publication activities.js LinkedBoardActivitiesBleed information disclosureEPSS 0.4%CVE-2024-37924MEDIUMWordPress WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin <= 1.0.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2020-15704MEDIUMpppd arbitrary file read information disclosure vulnerabilityEPSS 0.4%CVE-2024-38756MEDIUMWordPress Coming Soon Page – Responsive Coming Soon & Maintenance Mode plugin <= 1.6.3 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-54586HIGHGitProxy is susceptible to a hidden commits injection attackEPSS 0.4%CVE-2025-12297MEDIUMatjiu pybbs UserApiController.java information disclosureEPSS 0.4%CVE-2024-22260MEDIUMVMware Workspace One UEM update addresses an information exposure vulnerability.  A malicious actor with network access to the Workspace OneEPSS 0.4%CVE-2024-51769HIGHAn information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.EPSS 0.4%CVE-2025-60805HIGHAn issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via theEPSS 0.4%CVE-2026-101143MEDIUMEleveo Quality Management QMBODownload information disclosureEPSS 0.4%CVE-2026-71433MEDIUMLangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite storesEPSS 0.4%CVE-2024-25119MEDIUMInformation Disclosure of Encryption Key in TYPO3 Install ToolEPSS 0.4%CVE-2025-2786MEDIUMTempo-operator: serviceaccount token exposure leading to token and subject access reviews in openshift tempo operatorEPSS 0.4%CVE-2025-14980MEDIUMBetterDocs <= 4.3.3 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%CVE-2025-57433MEDIUMThe 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POST request to a speciEPSS 0.4%CVE-2026-76206MEDIUMphpMyFAQ before 4.1.7 Information Disclosure via PDF ExportEPSS 0.4%CVE-2025-69822HIGHAn issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privEPSS 0.4%CVE-2025-2228MEDIUMResponsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates <= 1.6.8 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%CVE-2024-12584MEDIUM140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6.2 - Authenticated (Contributor+) Post Disclosure via Post DuplicationEPSS 0.4%