Weaknesses of type CWE-200

4,979 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-41723MEDIUMBIG-IP iControl REST vulnerabilityEPSS 0.3%CVE-2026-23777MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release verEPSS 0.3%CVE-2026-73745LOWUnauthenticated Limited Information Disclosure allows Data Exposure in the API of HPE Networking Fabric ComposerEPSS 0.3%CVE-2023-0248HIGHKantech Gen1 ioSmart card readerEPSS 0.3%CVE-2025-30758MEDIUMVulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface). Supported versions that are affected areEPSS 0.3%CVE-2025-5098CRITICALKL-001-2025-003: Mobile Dynamix PrinterShare Mobile Print Gmail Oauth Token DisclosureEPSS 0.3%CVE-2026-62565HIGHVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported versions that are affeEPSS 0.3%CVE-2025-8039HIGHSearch terms persisted in URL barEPSS 0.3%CVE-2026-48855LOWSFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is ConfiguredEPSS 0.3%CVE-2024-41736MEDIUMInformation Disclosure vulnerability in SAP Permit to WorkEPSS 0.3%CVE-2024-39593MEDIUM[CVE-2024-39593] Information Disclosure vulnerability in SAP Landscape ManagementEPSS 0.3%CVE-2026-31869MEDIUMDiscourse: Composer mentions endpoint leaks hidden group membership through PM `allowed_names` checkEPSS 0.3%CVE-2026-1582LOWWP All Export <= 1.4.14 - Unauthenticated Sensitive Information Exposure via PHP Type JugglingEPSS 0.3%CVE-2023-0597MEDIUMA flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess lEPSS 0.3%CVE-2024-45805MEDIUMOpenCTI leaks support information due to inadequate access controlEPSS 0.3%CVE-2024-6426HIGHInformation exposure vulnerability vulnerability in MESbookEPSS 0.3%CVE-2024-34711CRITICALGeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)EPSS 0.3%CVE-2026-63640MEDIUMMagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variablesEPSS 0.3%CVE-2024-32387MEDIUMAn issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via thEPSS 0.3%CVE-2024-52001MEDIUMPortal user is able to access forbidden services information in Combodo iTopEPSS 0.3%