Weaknesses of type CWE-200

4,960 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-61112MEDIUMVulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions tEPSS 0.4%CVE-2026-62567HIGHVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are EPSS 0.4%CVE-2023-43123—Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary filesEPSS 0.4%CVE-2026-44460HIGHFileRise: TOTP Bypass via Setup Endpoint Disclosing Existing SecretEPSS 0.4%CVE-2023-52238LOWA vulnerability has been identified in RUGGEDCOM RST2228 (All versions < V5.9.0), RUGGEDCOM RST2228P (All versions < V5.9.0). The web serverEPSS 0.4%CVE-2025-66027HIGHRallly Information Disclosure Vulnerability in Participant API Leaks Names and Emails Despite Pro Privacy SettingsEPSS 0.4%CVE-2026-44506HIGHMedplum - Exposure of OAuth client secret via dynamic registration endpoint in self-hosted configurationsEPSS 0.4%CVE-2026-62556MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.4%CVE-2026-53643HIGHFOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpointsEPSS 0.4%CVE-2026-16960HIGHLoops & Logic < 4.3.0 - Unauthenticated User Data and Site Option DisclosureEPSS 0.4%CVE-2025-31964LOWHCL BigFix IVR is impacted by an improper service binding configurationEPSS 0.4%CVE-2026-53640LOWFOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect dataEPSS 0.4%CVE-2024-11299MEDIUMMemberpress <= 1.11.37 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.4%CVE-2026-2268HIGHNinja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX ActionEPSS 0.4%CVE-2025-40662MEDIUMAbsolute path disclosure vulnerability in DM Corporative CMSEPSS 0.4%CVE-2024-43319MEDIUMWordPress HTML5 Video Player plugin <= 2.5.31 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-48900MEDIUMMoodle: idor when accessing list of badge recipientsEPSS 0.4%CVE-2026-44408MEDIUMUnauthorized access vulnerability in ZTE MU5250EPSS 0.4%CVE-2023-44112HIGHOut-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiaEPSS 0.4%CVE-2025-6432HIGHDNS Requests leaked outside of a configured SOCKS proxyEPSS 0.4%