Weaknesses of type CWE-200

4,976 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-30118LOWHCL Connections is susceptible to a sensitive information disclosure vulnerabilityEPSS 0.3%CVE-2026-22600CRITICALOpenProject is Vulnerable to Arbitrary File Read via ImageMagick SVG CoderEPSS 0.3%CVE-2025-13439MEDIUMFancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Information Disclosure and PHAR Deserialization via 'url' ParameterEPSS 0.3%CVE-2024-42337MEDIUMCyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2023-22875HIGHIBM Security QRadar SIEM information disclosureEPSS 0.3%CVE-2021-20332MEDIUMMongoDB Rust Driver may publish events containing authentication-related data to a connection pool event listener configured by an applicationEPSS 0.3%CVE-2022-31066MEDIUMConfiguration API in EdgeXFoundry exposes message bus credentials to local unauthenticated usersEPSS 0.3%CVE-2024-32385MEDIUMAn issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a EPSS 0.3%CVE-2022-45459LOWSensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before bEPSS 0.3%CVE-2024-9542MEDIUMSky Addons for Elementor <= 2.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Content Switcher Widget Elementor TemplateEPSS 0.3%CVE-2026-54317HIGHHome Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LANEPSS 0.3%CVE-2024-8494MEDIUMElementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via ShortcodeEPSS 0.3%CVE-2026-54276MEDIUMAIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect ChallengesEPSS 0.3%CVE-2026-61267HIGHVulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versEPSS 0.3%CVE-2023-24588MEDIUMExposure of sensitive information to an unauthorized actor in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticateEPSS 0.3%CVE-2024-45391HIGHTina search token leak via lock file in TinaCMSEPSS 0.3%CVE-2026-75839MEDIUMArcadeDB before 26.8.1 Information Disclosure via Cluster EndpointsEPSS 0.3%CVE-2026-91981MEDIUMVikunja before 2.6.0 User Enumeration via v2 APIEPSS 0.3%CVE-2026-48210MEDIUMPossible information disclosure via External InterfaceEPSS 0.3%CVE-2026-65009MEDIUMOpenRemote before 1.26.2 Information Disclosure via Syslog REST APIEPSS 0.3%