Weaknesses of type CWE-200

4,979 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-14231MEDIUMLifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_postsEPSS 0.3%CVE-2026-87032MEDIUMTanium addressed an information disclosure vulnerability in Tanium Server.EPSS 0.3%CVE-2026-63240MEDIUMInformation disclosure vulnerabilityEPSS 0.3%CVE-2026-85349MEDIUMFluentBoards < 2.0.15 - Subscriber+ Private Board Membership Disclosure via IDOREPSS 0.3%CVE-2026-22604MEDIUMOpenProject is vulnerable to user enumeration via the change password functionEPSS 0.3%CVE-2026-85572MEDIUMTutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment DisclosureEPSS 0.3%CVE-2026-14226MEDIUMEasy Appointments < 3.12.28 - Subscriber+ Sensitive Information Disclosure via REST Appointments ListingEPSS 0.3%CVE-2020-10782MEDIUMAn exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be EPSS 0.3%CVE-2026-22602LOWOpenProject is Vulnerable to User Enumeration via User IDEPSS 0.3%CVE-2026-49355MEDIUMOpenProject: Private work package data disclosure through single meeting agenda item APIEPSS 0.3%CVE-2025-1115MEDIUMRT-Thread lwp_syscall.c sys_timer_settime information disclosureEPSS 0.3%CVE-2025-61906LOWOpencast's editor accidentally publishes videos/overwrites publications #1626EPSS 0.3%CVE-2022-42819MEDIUMAn access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS MontereyEPSS 0.3%CVE-2026-78146MEDIUMNoptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure via Actions PageEPSS 0.3%CVE-2026-28415MEDIUMGradio has Open Redirect in OAuth FlowEPSS 0.3%CVE-2025-61589MEDIUMCursor: Potential Information Leakage via Mermaid DiagramEPSS 0.3%CVE-2025-12770MEDIUMNew User Approve <= 3.0.9 - Unauthenticated Sensitive Information Disclosure via Type JugglingEPSS 0.3%CVE-2026-14096MEDIUMInappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the rEPSS 0.3%CVE-2025-59018HIGHInformation Disclosure in Workspaces ModuleEPSS 0.3%CVE-2026-14098MEDIUMInappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafteEPSS 0.3%