Weaknesses of type CWE-200

4,974 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-81021MEDIUMSupportCandy 3.2.9 - 3.5.2 - Unauthenticated Ticket Attachment DisclosureEPSS 0.3%CVE-2026-77754MEDIUMKirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apisEPSS 0.3%CVE-2024-10365MEDIUMThe Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.0.3 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplatesEPSS 0.3%CVE-2017-20210CRITICALPhoto StationEPSS 0.3%CVE-2026-77782MEDIUMRank Math SEO < 1.0.277.1 - Unauthenticated Password-Protected Post Content Disclosure via Post Metadata and llms.txtEPSS 0.3%CVE-2026-80340MEDIUMPayment Plugins for PayPal WooCommerce < 2.0.26 - Unauthenticated Customer PII Disclosure via order-payEPSS 0.3%CVE-2026-86445MEDIUMLearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_content_via_ajaxEPSS 0.3%CVE-2024-39807LOWChannel IDs of archived/restored channels leaked via webhook eventsEPSS 0.3%CVE-2026-81197MEDIUMMasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosure via course-list REST RouteEPSS 0.3%CVE-2024-23228MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 17.3 and iPadOS 17.3. Locked Notes content may have bEPSS 0.3%CVE-2026-81022MEDIUMSupportCandy 3.3.6 - 3.5.2 - Unauthenticated Ticket Content Disclosure via Auth Code LeakEPSS 0.3%CVE-2024-12340MEDIUMAnimation Addons for Elementor <= 1.1.6 - Authenticated (Contributor+) Sensitive Information Exposure via Content Slider and Tabs Widget Elementor TemplateEPSS 0.3%CVE-2024-10352MEDIUMMagical Addons For Elementor <= 1.2.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplateEPSS 0.3%CVE-2025-15103HIGHDVP-12SE11T - Authentication Bypass via Partial Password DisclosureEPSS 0.3%CVE-2024-9889MEDIUMElementInvader Addons for Elementor <= 1.2.9 - Authenticated (Contributor+) Information ExposureEPSS 0.3%CVE-2024-9541MEDIUMNews Kit Elementor Addons <= 1.2.1 - Authenticated (Contributor+) Sensitive Information Exposure via Canvas Menu Elementor TemplateEPSS 0.3%CVE-2024-34754MEDIUMWordPress Contact Form Widget plugin <= 1.3.9 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-46659HIGHAn issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HTTPS request.EPSS 0.3%CVE-2024-10319MEDIUM140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplateEPSS 0.3%CVE-2026-37454HIGHInsecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via EPSS 0.3%