Weaknesses of type CWE-200

4,960 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-40723HIGHAn exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and EPSS 0.4%CVE-2026-47263MEDIUMDiscourse: Prevent webhook payload disclosure on event redeliveryEPSS 0.4%CVE-2025-8590HIGHInformation Disclosure in AKCE Software's SKSProEPSS 0.4%CVE-2024-56197LOWUsers can see other user's tagged PMs in DiscourseEPSS 0.4%CVE-2024-5202HIGHDimensions RM - Arbitrary File ReadEPSS 0.4%CVE-2026-73055MEDIUMShescape before 2.1.15 and 3.0.2 Home Directory Disclosure via BusyBoxEPSS 0.4%CVE-2026-71849LOWHono: Proxy Helper does not remove response headers listed in the `Connection` headerEPSS 0.4%CVE-2026-35413MEDIUMDirectus GraphQL Schema SDL Disclosure SettingEPSS 0.4%CVE-2025-1063MEDIUMClassified Listing – Classified ads & Business Directory Plugin <= 4.0.4 - Unauthenticated Settings ExposureEPSS 0.4%CVE-2023-48714MEDIUMRecord titles for restricted records can be viewed if exposed by GridFieldAddExistingAutocompleterEPSS 0.4%CVE-2026-28976HIGHAn information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root prEPSS 0.4%CVE-2025-0318MEDIUMUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information ExposureEPSS 0.4%CVE-2024-34003MEDIUMmoodle: authenticated LFI risk in some misconfigured shared hosting environments via modified mod_workshop backupEPSS 0.4%CVE-2026-32099MEDIUMDiscourse prevents hidden profile data leak via user oneboxEPSS 0.4%CVE-2026-48771HIGHishankportfolio: Stored Contact Form Submission Exposure via Public Client-Side Database ConfigurationEPSS 0.4%CVE-2025-27827HIGHA vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthenticated attacker to EPSS 0.4%CVE-2023-42884MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.EPSS 0.4%CVE-2025-29486MEDIUMlibming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.EPSS 0.4%CVE-2018-0267—A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view sensitive EPSS 0.4%CVE-2024-13451MEDIUMContact Form by Bit Form <= 2.17.5 - Unauthenticated Sensitive Information ExposureEPSS 0.4%