Weaknesses of type CWE-200

4,960 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-48131MEDIUMAn issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel acEPSS 0.4%CVE-2023-48132MEDIUMAn issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via lEPSS 0.4%CVE-2025-20325LOWSensitive Information Disclosure in the SHCConfig logging channel in Clustered Deployments in Splunk EnterpriseEPSS 0.4%CVE-2025-14574MEDIUMweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.1.15 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2025-69226MEDIUMAIOHTTP allows for a brute-force leak of internal static filepath componentsEPSS 0.4%CVE-2023-48130MEDIUMAn issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access tEPSS 0.4%CVE-2023-48129MEDIUMAn issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel accesEPSS 0.4%CVE-2026-50105MEDIUMRSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)EPSS 0.4%CVE-2019-1815HIGHCisco Meraki MX67 and MX68 Sensitive Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-48135MEDIUMAn issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel accesEPSS 0.4%CVE-2024-1405MEDIUMLinksys WRT54GL Web Management Interface wlaninfo.htm information disclosureEPSS 0.4%CVE-2026-8058MEDIUMThis Power System update is being released to address a sensitive information disclosureEPSS 0.4%CVE-2026-90538MEDIUMWWBN AVideo Missing Authorization via playlistsFromUser.json.phpEPSS 0.4%CVE-2026-6801MEDIUMContext Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' ParameterEPSS 0.4%CVE-2026-56284MEDIUMCapgo - Unauthenticated Metrics Disclosure via get_total_metrics RPCEPSS 0.4%CVE-2025-63212MEDIUMGatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifieEPSS 0.4%CVE-2026-37069MEDIUMAbsolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allEPSS 0.4%CVE-2022-4862MEDIUMXSS vulnerability in M-Files WebEPSS 0.4%CVE-2026-18809MEDIUMInformation disclosure in Firefox for Android and Firefox Focus for AndroidEPSS 0.4%CVE-2026-41182MEDIUMLangSmith SDK: Streaming token events bypass output redactionEPSS 0.4%