Weaknesses of type CWE-200

4,960 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-10084MEDIUMContact Form 7 – Dynamic Text Extension <= 4.5 - Information Disclosure via ShortcodeEPSS 0.4%CVE-2026-31951MEDIUMLibreChat's MCP Server Header Injection Enables OAuth Token TheftEPSS 0.4%CVE-2021-3732—A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows EPSS 0.4%CVE-2024-7063MEDIUMElementsKit Pro <= 3.6.6 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.4%CVE-2026-34947LOWDiscourse: Staged user custom fields are exposed on public invite pagesEPSS 0.4%CVE-2024-21902MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2026-46912CRITICALVulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions thatEPSS 0.4%CVE-2024-34529MEDIUMNebari through 2024.4.1 prints the temporary Keycloak root password.EPSS 0.4%CVE-2025-12512MEDIUMGenerateBlocks <= 2.1.2 - Authenticated (Contributor+) Information Exposure via MetadataEPSS 0.4%CVE-2026-60969HIGHVulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affectEPSS 0.4%CVE-2023-52238LOWA vulnerability has been identified in RUGGEDCOM RST2228 (All versions < V5.9.0), RUGGEDCOM RST2228P (All versions < V5.9.0). The web serverEPSS 0.4%CVE-2026-44460HIGHFileRise: TOTP Bypass via Setup Endpoint Disclosing Existing SecretEPSS 0.4%CVE-2026-44506HIGHMedplum - Exposure of OAuth client secret via dynamic registration endpoint in self-hosted configurationsEPSS 0.4%CVE-2025-66027HIGHRallly Information Disclosure Vulnerability in Participant API Leaks Names and Emails Despite Pro Privacy SettingsEPSS 0.4%CVE-2026-61112MEDIUMVulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions tEPSS 0.4%CVE-2026-62560HIGHVulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are EPSS 0.4%CVE-2023-44097—Vulnerability of the permission to access device SNs being improperly managed.Successful exploitation of this vulnerability may affect serviEPSS 0.4%CVE-2026-62567HIGHVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are EPSS 0.4%CVE-2026-33745HIGHcpp-httplib Client Leaks Authentication Credentials to Untrusted Hosts on Cross-Origin HTTP RedirectEPSS 0.4%CVE-2025-53512MEDIUMSensitive log retrieval in JujuEPSS 0.4%