Weaknesses of type CWE-200

4,909 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2020-26869HIGHARC Informatique PcVue Exposure of Sensitive Information to an Unauthorized ActorEPSS 1.7%CVE-2020-26230HIGHDeanonymization of COVID-19 positive users of Radar COVIDEPSS 1.7%CVE-2019-1228MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 1.7%CVE-2019-1227MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 1.7%CVE-2023-42781—Apache Airflow: Permission verification bypass allows viewing dagruns of other dagsEPSS 1.7%CVE-2022-0235HIGHExposure of Sensitive Information to an Unauthorized Actor in node-fetch/node-fetchEPSS 1.7%CVE-2021-41092MEDIUMDocker CLI leaks private registry credentials to registry-1.docker.ioEPSS 1.7%CVE-2022-24737MEDIUMExposure of Sensitive Information to an Unauthorized Actor in httpieEPSS 1.7%CVE-2024-54961MEDIUMNagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying theEPSS 1.6%CVE-2025-6984HIGHSensitive Information Disclosure Due to Insecure XML Parsing in langchain-ai/langchainEPSS 1.6%CVE-2023-46851—Apache Allura: sensitive information exposure via importEPSS 1.6%CVE-2025-21242MEDIUMWindows Kerberos Information Disclosure VulnerabilityEPSS 1.6%CVE-2025-4751MEDIUMD-Link DI-7003GV2 index.data information disclosureEPSS 1.6%CVE-2024-13609MEDIUM1 Click WordPress Migration Plugin – 100% FREE for a limited time <= 2.2 - Unauthenticated Sensitive Information Exposure via Database Backup in class-ocm-backup.phpEPSS 1.6%CVE-2018-13289MEDIUMInformation exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers tEPSS 1.6%CVE-2020-36848HIGHTotal Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup DownloadEPSS 1.6%CVE-2017-2651LOWjenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamicallyEPSS 1.6%CVE-2020-3498MEDIUMCisco Jabber for Windows Information Disclosure VulnerabilityEPSS 1.6%CVE-2018-14782—NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration filEPSS 1.6%CVE-2022-0709—Booking Package < 1.5.29 - Unauthenticated Sensitive Data DisclosureEPSS 1.6%