Weaknesses of type CWE-200

4,974 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-85156MEDIUMWWBN AVideo Broken Access Control via Channel PageEPSS 0.3%CVE-2026-87810MEDIUMSiyuan before v3.8.2 Information Disclosure via fullTextSearchBlockEPSS 0.3%CVE-2026-92044HIGHInformation disclosure in the Networking: HTTP componentEPSS 0.3%CVE-2026-48078MEDIUMOpenReception's schedule endpoint discloses isPublic=false channels and slot availability to unauthenticated callersEPSS 0.3%CVE-2026-85157MEDIUMWWBN AVideo Broken Access Control via feed/index.php program_idEPSS 0.3%CVE-2026-27463MEDIUMCombodo iTop: Version disclosure via login page logoEPSS 0.3%CVE-2026-56336MEDIUMCapgo - Information Disclosure via Unauthenticated SSO check-domain EndpointEPSS 0.3%CVE-2026-27452CRITICALASN.1 TypeScript Library: Decoding an INTEGER could leak the underlying ArrayBufferEPSS 0.3%CVE-2018-15615HIGHCMS Supervisor Information DisclosureEPSS 0.3%CVE-2026-56218MEDIUMCapgo - EXIF Metadata Exposure via Image UploadEPSS 0.3%CVE-2023-52341HIGHIn Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to EPSS 0.3%CVE-2026-37454HIGHInsecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via EPSS 0.3%CVE-2025-20207MEDIUMCisco Secure Email Gateway, Cisco Secure Email and Web Appliance and Cisco Secure Web Appliance SNMP Polling Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-43237MEDIUMWordPress Tag Groups plugin <= 2.0.3 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2026-64664MEDIUMStatamic: Missing authorization on Control Panel endpoint allows disclosure of user existenceEPSS 0.3%CVE-2026-16964MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2025-15508MEDIUMMagic Import Document Extractor <= 1.0.6 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2025-29497MEDIUMlibming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.EPSS 0.3%CVE-2025-29489MEDIUMlibming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.EPSS 0.3%CVE-2026-33161LOWCraft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized usersEPSS 0.3%