Weaknesses of type CWE-200

4,976 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-39210LOWAccess to internal files of the Nextcloud Android appEPSS 0.3%CVE-2026-102845MEDIUMgedelumbung HospitalManagement HTTP Response index.php error_reporting information disclosureEPSS 0.3%CVE-2026-28511MEDIUMelabftw has entry title leakage through autocompletion searchEPSS 0.3%CVE-2024-40798LOWThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS MonterEPSS 0.3%CVE-2026-45387MEDIUMOpen WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)EPSS 0.3%CVE-2025-4659MEDIUMIntegration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.4 - Unauthenticated Full Path DisclosureEPSS 0.3%CVE-2026-86448LOWLearnPress < 4.4.7 - Unauthenticated Order Data Disclosure via lp_download_orderEPSS 0.3%CVE-2023-49774MEDIUMWordPress WP Photo Album Plus plugin <= 8.5.02.005 - IP Bypass vulnerabilityEPSS 0.3%CVE-2025-11379MEDIUMWebP Express <= 0.25.9 - Unauthenticated Information ExposureEPSS 0.3%CVE-2022-42810MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, tvOS 16.1, iOS 16.1 and iPadOS 1EPSS 0.3%CVE-2025-6425MEDIUMThe WebCompat WebExtension shipped with Firefox exposed a persistent UUIDEPSS 0.3%CVE-2023-49367HIGHAn issue in user interface in Kyocera Command Center RX EXOSYS M5521cdn allows remote to obtain sensitive information via inspecting sent paEPSS 0.3%CVE-2026-1669HIGHArbitrary File Read in Keras via HDF5 External DatasetsEPSS 0.3%CVE-2025-60925MEDIUMcodeshare v1.0.0 was discovered to contain an information leakage vulnerability.EPSS 0.3%CVE-2022-42854MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1. An app may be able EPSS 0.3%CVE-2026-4994MEDIUMwandb OpenUI APIStatusError server.py generic_exception_handler information exposureEPSS 0.3%CVE-2024-41701MEDIUMAccuPOS – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2021-41181LOWNextcloud Talk app exposes chat messages on lockscreenEPSS 0.3%CVE-2025-13439MEDIUMFancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Information Disclosure and PHAR Deserialization via 'url' ParameterEPSS 0.3%CVE-2024-5524MEDIUMInformation exposure vulnerability in AstrotalksEPSS 0.3%