Weaknesses of type CWE-200

4,975 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-100377MEDIUMRevision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbstractEPSS 0.3%CVE-2026-100379MEDIUMCross-request disclosure of CentralAuth cookies in Wikipedia Android AppEPSS 0.3%CVE-2026-60349MEDIUMVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are EPSS 0.3%CVE-2024-39335CRITICALSupported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution aEPSS 0.3%CVE-2025-6722MEDIUMBitFire <= 4.5 - Unauthenticated Information ExposureEPSS 0.3%CVE-2026-44779MEDIUMDiscourse: Bot debug endpoints disclose whisper translation audit logsEPSS 0.3%CVE-2025-4523MEDIUMIDonate 2.0.0 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view FunctionEPSS 0.3%CVE-2026-61081LOWVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Supported versions that aEPSS 0.3%CVE-2026-14314MEDIUMPeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attachment Disclosure via IDOREPSS 0.3%CVE-2026-17585MEDIUMRoyal Addons for Elementor <= 1.7.1066 - Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' ParameterEPSS 0.3%CVE-2026-70590MEDIUMGhost: Blind Password Hash Disclosure in Ghost Admin APIEPSS 0.3%CVE-2026-11357MEDIUMKadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData LocalizationEPSS 0.3%CVE-2026-16391HIGHInformation disclosure in the Storage: IndexedDB componentEPSS 0.3%CVE-2023-52147LOWWordPress All-In-One Security (AIOS) plugin <= 5.2.4 - Secret Login Page Location Disclosure on Multisites vulnerabilityEPSS 0.3%CVE-2026-16374HIGHInformation disclosure in the Framework component in DevToolsEPSS 0.3%CVE-2025-15070MEDIUMData Exposure in Gmission Web FAXEPSS 0.3%CVE-2026-92548MEDIUMWP Popular Posts <= 7.4.2 - Unauthenticated Information Disclosure in 'post_type' and 'context' ParametersEPSS 0.3%CVE-2026-62865HIGHTypeBot: Arbitrary server file read via Send Email block attachment pathEPSS 0.3%CVE-2026-33422LOWDiscourse exposes ip_address of flagged userEPSS 0.3%CVE-2025-0227MEDIUMTsinghua Unigroup Electronic Archives System downLoad.html information disclosureEPSS 0.3%