Weaknesses of type CWE-200

4,975 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-84926LOWEmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST RouteEPSS 0.3%CVE-2026-19858HIGHJetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosure via Dynamic PresetEPSS 0.3%CVE-2026-87836LOWComments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via ExportEPSS 0.3%CVE-2026-19406LOWEasy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via REST Appointments ListingEPSS 0.3%CVE-2026-59180LOWApprise forwards configured auth headers across cross-origin HTTP redirectsEPSS 0.3%CVE-2022-0851—There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subEPSS 0.3%CVE-2025-20270MEDIUMCisco Evolved Programmable Network Manager Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-63432MEDIUMHorilla: Server-Side Template Injection (SSTI) in Mail Preview Endpoints Allows Authenticated Users to Disclose Password Hashes and Server MetadataEPSS 0.3%CVE-2024-58256MEDIUMEnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.EPSS 0.3%CVE-2026-101083MEDIUMPMWeb encryptionhelper.dll information disclosureEPSS 0.3%CVE-2026-20360HIGHCisco Nexus Dashboard Software Security Hardening Release September 2026 - Information Exposure & Insecure HandlingEPSS 0.3%CVE-2023-50346LOWAn information disclosure affects DRYiCE MyXalyticsEPSS 0.3%CVE-2026-65758HIGHJoomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2EPSS 0.3%CVE-2024-27731MEDIUMCross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file typeEPSS 0.3%CVE-2025-26485MEDIUMA vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts (in case of the usaEPSS 0.3%CVE-2025-11760MEDIUMeRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams <= 1.5.6 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2026-60888MEDIUMVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.3%CVE-2025-8484MEDIUMCode Quality Control Tool <= 2.1 - Unauthenticated Information Exposure via Log FilesEPSS 0.3%CVE-2026-61050MEDIUMVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: User Interface). Supported versions that aEPSS 0.3%CVE-2026-62490MEDIUMVulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.3%