Weaknesses of type CWE-200

4,976 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-50200HIGHSteeltoe's env sanitizer misses connection strings — leaks embedded DB passwordsEPSS 0.3%CVE-2026-5075MEDIUMAll in One SEO <= 4.9.7 - Authenticated (Contributor+) Sensitive Information Exposure via 'internalOptions' Localized Script DataEPSS 0.3%CVE-2026-75839MEDIUMArcadeDB before 26.8.1 Information Disclosure via Cluster EndpointsEPSS 0.3%CVE-2026-90936MEDIUMFroxlor before 2.3.7 Information Disclosure via customer_email.phpEPSS 0.3%CVE-2026-48210MEDIUMPossible information disclosure via External InterfaceEPSS 0.3%CVE-2026-65009MEDIUMOpenRemote before 1.26.2 Information Disclosure via Syslog REST APIEPSS 0.3%CVE-2024-45391HIGHTina search token leak via lock file in TinaCMSEPSS 0.3%CVE-2025-12785MEDIUMCertain HP LaserJet Pro Printers – Potential Information DisclosureEPSS 0.3%CVE-2026-42195LOWUnvalidated gitlab URL parameter redirects OAuth authorize step to attacker-controlled hostEPSS 0.3%CVE-2023-34242LOWCilium vulnerable to information leakage via incorrect ReferenceGrant handlingEPSS 0.3%CVE-2025-57755HIGHclaude-code-router CORS. misconfigurationEPSS 0.3%CVE-2025-52026HIGHAn information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-EPSS 0.3%CVE-2026-62249MEDIUMWeblate: Restricted-component change history leaked to non-member project users through the nested `GET /api/projects/{slug}/changes/` endpointEPSS 0.3%CVE-2025-61481CRITICALAn issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an oEPSS 0.3%CVE-2025-41015MEDIUMUser Enumeration vulnerability in TCMAN GIMEPSS 0.3%CVE-2026-79193MEDIUMInformation leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak cross-origin data via a crafted HTML paEPSS 0.3%CVE-2025-41014MEDIUMUser Enumeration vulnerability in TCMAN GIMEPSS 0.3%CVE-2025-57757MEDIUMContao discloses information in the news moduleEPSS 0.3%CVE-2025-56467MEDIUMAn issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, suEPSS 0.3%CVE-2026-60408MEDIUMVulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The suppoEPSS 0.3%