Weaknesses of type CWE-200

4,974 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-33161LOWCraft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized usersEPSS 0.3%CVE-2025-29489MEDIUMlibming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.EPSS 0.3%CVE-2025-29497MEDIUMlibming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.EPSS 0.3%CVE-2026-35449MEDIUMWWBN AVideo has Unauthenticated Information Disclosure via Disabled CLI Guard in install/test.phpEPSS 0.3%CVE-2026-48189MEDIUMBypass DedicatedAgentToCustomerGroups SettingEPSS 0.3%CVE-2025-20129MEDIUMCisco Customer Collaboration Platform Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-47059MEDIUMUsers enumeration - weak password loginEPSS 0.3%CVE-2026-61185HIGHVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The sEPSS 0.3%CVE-2018-17956LOWPassword exposed in process listingEPSS 0.3%CVE-2019-18947LOWinformation disclosureEPSS 0.3%CVE-2025-5690MEDIUMCursor allows PostgreSQL Anonymizer masked user to gain unauthorized access to authentic dataEPSS 0.3%CVE-2024-6551MEDIUMGiveWP <= 3.15.1 - Unauthenticated Full Path DisclosureEPSS 0.3%CVE-2022-33159MEDIUMIBM Security Directory Suite VA information disclosureEPSS 0.3%CVE-2026-16354HIGHInformation disclosure in the Graphics: ImageLib componentEPSS 0.3%CVE-2026-64761HIGHA privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 27 and iPadOS 27. An app may be able toEPSS 0.3%CVE-2023-52097HIGHVulnerability of foreground service restrictions being bypassed in the NMS module.Successful exploitation of this vulnerability may affect sEPSS 0.3%CVE-2023-4272MEDIUMMali GPU Kernel Driver exposes sensitive data from freed memoryEPSS 0.3%CVE-2025-23073LOWAPI list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets parameterEPSS 0.3%CVE-2026-49397MEDIUMNezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing dataEPSS 0.3%CVE-2026-49463MEDIUMNL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-librariesEPSS 0.3%