Weaknesses of type CWE-200

4,979 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-32387MEDIUMAn issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via thEPSS 0.3%CVE-2026-55188HIGHRustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentialsEPSS 0.3%CVE-2024-52001MEDIUMPortal user is able to access forbidden services information in Combodo iTopEPSS 0.3%CVE-2026-83354MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.EPSS 0.3%CVE-2026-79122MEDIUMInformation leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted netEPSS 0.3%CVE-2025-13758LOWExposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.EPSS 0.3%CVE-2025-24089MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumeEPSS 0.3%CVE-2024-52032MEDIUMPrivate channel names leaking when Elasticsearch is enabledEPSS 0.3%CVE-2023-47616LOWA CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8EPSS 0.3%CVE-2026-1407LOWBeetel 777VR1 UART information disclosureEPSS 0.3%CVE-2026-79246MEDIUMInformation leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a craEPSS 0.3%CVE-2025-14075MEDIUMWP Hotel Booking <= 2.2.7 - Unauthenticated Sensitive Information Exposure via 'email' ParameterEPSS 0.3%CVE-2025-4593MEDIUMWP Register Profile With Shortcode <= 3.6.2 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.3%CVE-2024-36118LOWUnauthorized viewing of workspace test cases in MeterSphereEPSS 0.3%CVE-2024-34029MEDIUMAD/LDAP Group Members LeakEPSS 0.3%CVE-2018-0106—A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access EPSS 0.3%CVE-2026-14231MEDIUMLifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_postsEPSS 0.3%CVE-2026-78138MEDIUMFinale Lite < 2.21.0 - Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_htmlEPSS 0.3%CVE-2026-1255HIGHYS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Unauthenticated Information Disclosure in 'ysleadgen_get_captured_data' AJAX ActionEPSS 0.3%CVE-2026-85572MEDIUMTutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment DisclosureEPSS 0.3%