Weaknesses of type CWE-200

4,974 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-105030MEDIUMKener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard APIEPSS 0.3%CVE-2026-58425MEDIUMOAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)EPSS 0.3%CVE-2026-58510MEDIUMGHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->privateEPSS 0.3%CVE-2024-41698MEDIUMPriority – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2024-28188MEDIUMjupyter-scheduler's endpoint is missing authenticationEPSS 0.3%CVE-2026-12120MEDIUMFireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in 'form_id' ParameterEPSS 0.3%CVE-2026-32100MEDIUMswag/platform-security: `/api/_info/config` route exposes information about licenses and active security fixesEPSS 0.3%CVE-2026-84146MEDIUMXpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclosure via Quick ViewEPSS 0.3%CVE-2024-20910LOWVulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. DifficEPSS 0.3%CVE-2026-56728MEDIUMZammad: Cross-User Taskbar Item Access Control VulnerabilityEPSS 0.3%CVE-2026-78152MEDIUMSureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person SchemaEPSS 0.3%CVE-2026-80423HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.3%CVE-2026-32142MEDIUMshopware/commercial: `/api/_info/config` route exposes information about licensesEPSS 0.3%CVE-2026-1267MEDIUMIBM Planning Analytics Information DisclosureEPSS 0.3%CVE-2026-1371MEDIUMTutor LMS <= 3.9.5 - Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX ActionEPSS 0.3%CVE-2025-13660MEDIUMGuest Support <= 1.2.3 - Unauthenticated User Email Disclosure in guest_support_handler AJAX EndpointEPSS 0.3%CVE-2026-10254MEDIUMSourceCodester Pet Grooming Management Software admin file information disclosureEPSS 0.3%CVE-2025-4390MEDIUMWP Private Content Plus <= 3.6.2 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2025-23215CRITICALPMD Designer's release key passphrase (GPG) available on Maven Central in cleartextEPSS 0.3%CVE-2026-90899HIGHJoomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0EPSS 0.3%