Weaknesses of type CWE-200

4,975 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-61220HIGHThe incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other users and gain unauEPSS 0.3%CVE-2021-3602—An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds EPSS 0.3%CVE-2020-3541MEDIUMCisco Webex Meetings Client for Windows, Webex Meetings Desktop App, and Webex Teams Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-9129CRITICALPath Traversal in Altium Enterprise Server Viewer StorageController Allows Arbitrary File ReadEPSS 0.3%CVE-2026-34244MEDIUMWeblate: SSRF via Project-Level Machinery ConfigurationEPSS 0.3%CVE-2017-12315—A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local aEPSS 0.3%CVE-2026-25125MEDIUMOctober CMS: Environment Variable Exfiltration via INI Parser InterpolationEPSS 0.3%CVE-2024-28164MEDIUMInformation Disclosure vulnerability in SAP NetWeaver AS Java (Guided Procedures)EPSS 0.3%CVE-2026-28506MEDIUMOutline's Information Disclosure in Activity Logs allows User Enumeration of Private DraftsEPSS 0.3%CVE-2026-34092LOWBlock UI elements in 'tools'-sidebar shows presence of an autoblocked IPEPSS 0.3%CVE-2026-18486HIGHIBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter executionEPSS 0.3%CVE-2025-3104MEDIUMWP Staging Pro <= 6.1.2 - Unauthenticated Information Exposure via getOutdatedPluginsRequest FunctionEPSS 0.3%CVE-2025-12585MEDIUMMxChat – AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information ExposureEPSS 0.3%CVE-2026-21928MEDIUMVulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exEPSS 0.3%CVE-2025-29992HIGHMahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being teEPSS 0.3%CVE-2024-39335CRITICALSupported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution aEPSS 0.3%CVE-2026-20298MEDIUMSensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk EnterpriseEPSS 0.3%CVE-2026-100377MEDIUMRevision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbstractEPSS 0.3%CVE-2026-60349MEDIUMVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are EPSS 0.3%CVE-2025-60858HIGHReolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration and update scripts,EPSS 0.3%