Weaknesses of type CWE-200

4,960 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-41182MEDIUMLangSmith SDK: Streaming token events bypass output redactionEPSS 0.4%CVE-2026-8058MEDIUMThis Power System update is being released to address a sensitive information disclosureEPSS 0.4%CVE-2026-37069MEDIUMAbsolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allEPSS 0.4%CVE-2025-63212MEDIUMGatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifieEPSS 0.4%CVE-2026-61454HIGHGrav before 2.0.4 Information Disclosure via __GRAV_CONFIG__EPSS 0.4%CVE-2025-26604HIGHPossibility to retrieve bot token by malicious module developers in Discord-Bot-Framework-KernelEPSS 0.4%CVE-2026-6801MEDIUMContext Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' ParameterEPSS 0.4%CVE-2026-57994MEDIUMphpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API EndpointsEPSS 0.4%CVE-2022-4862MEDIUMXSS vulnerability in M-Files WebEPSS 0.4%CVE-2024-47060MEDIUMUnauthorized Access After Organization or Project Deactivation in ZitadelEPSS 0.4%CVE-2019-1731MEDIUMCisco NX-OS Software SSH Key Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-47264MEDIUMDiscourse: Don't leak restricted tag group names via tag infoEPSS 0.4%CVE-2017-12284—A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to retrieve user profilEPSS 0.4%CVE-2024-56526HIGHAn issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a SEPSS 0.4%CVE-2025-7573MEDIUMLB-LINK BL-WR9000 lighttpd.cgi bs_GetManPwd information disclosureEPSS 0.4%CVE-2025-66625MEDIUMUmbraco Vulnerable to Improper File Access and Credential Exposure through Dictionary Import FunctionalityEPSS 0.4%CVE-2025-27399MEDIUMMastodon's domain blocks & rationales ignore user approval when visibility set as "users"EPSS 0.4%CVE-2025-7572MEDIUMLB-LINK BL-WR9000 lighttpd.cgi bs_GetHostInfo information disclosureEPSS 0.4%CVE-2023-50872HIGHThe API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial informationEPSS 0.4%CVE-2026-47263MEDIUMDiscourse: Prevent webhook payload disclosure on event redeliveryEPSS 0.4%