Weaknesses of type CWE-200

4,959 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-12584MEDIUM140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6.2 - Authenticated (Contributor+) Post Disclosure via Post DuplicationEPSS 0.4%CVE-2026-55496MEDIUMCloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicateEPSS 0.4%CVE-2020-1739LOWA flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svEPSS 0.4%CVE-2025-59454MEDIUMApache CloudStack: Lack of user permission validation leading to data leak for few APIsEPSS 0.4%CVE-2026-9183MEDIUM24liveblog <= 2.2 - Authenticated (Contributor+) Exposure of Sensitive Information via Block Editor Script LocalizationEPSS 0.4%CVE-2025-39204HIGHA vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, sEPSS 0.4%CVE-2026-41183MEDIUMFreeScout allows non-folder conversation queries to disclose assigned-only hidden conversationsEPSS 0.4%CVE-2026-34600MEDIUMJoplin Server delta API returns note content after share access is revokedEPSS 0.4%CVE-2025-8852MEDIUMWuKongOpenSource WukongCRM API Response upload information exposureEPSS 0.4%CVE-2025-58589LOWInformation Disclosure Through StacktraceEPSS 0.4%CVE-2025-54468MEDIUMRancher sends sensitive information to external services through the `/meta/proxy` endpointEPSS 0.4%CVE-2023-43997MEDIUMAn issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channelEPSS 0.4%CVE-2023-5160MEDIUMFull name disclosure via team top membership with Show Full Name option disabledEPSS 0.4%CVE-2023-43994MEDIUMAn issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel aEPSS 0.4%CVE-2023-43995MEDIUMAn issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access tEPSS 0.4%CVE-2026-61782HIGH@rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build MetadataEPSS 0.4%CVE-2023-43992MEDIUMAn issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel acceEPSS 0.4%CVE-2025-13526HIGHOneClick Chat to Order <= 1.0.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2026-45739LOWStrawberry GraphQL: Default GraphiQL may expose HTTP headers in URLsEPSS 0.4%CVE-2024-12329MEDIUMEssential Real Estate <= 5.1.6 - Missing Authorization to Authenticated (Contributor+) Information ExposureEPSS 0.4%