Weaknesses of type CWE-200

4,979 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-22602LOWOpenProject is Vulnerable to User Enumeration via User IDEPSS 0.3%CVE-2025-12545MEDIUMPixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more <= 1.49.2 - Unauthenticated Information ExposureEPSS 0.3%CVE-2025-12525MEDIUMLocker Content <= 1.0.0 - Unauthenticated Information ExposureEPSS 0.3%CVE-2025-13113MEDIUMWeb Accessibility by accessiBe <= 2.11 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2026-78960MEDIUMInformation leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain croEPSS 0.3%CVE-2025-12681MEDIUMComment Edit Core – Simple Comment Editing <= 3.1.0 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2026-100632HIGHParse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQueryEPSS 0.3%CVE-2025-2860MEDIUMExposure of Sensitive Information vulnerability in saTECH BCUEPSS 0.3%CVE-2021-0166MEDIUMExposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systemsEPSS 0.3%CVE-2025-13006MEDIUMSurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information ExposureEPSS 0.3%CVE-2025-13494MEDIUMSSP Debug <= 1.0.0 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2026-33073LOWdiscourse-subscriptions plugin leaking stripe API key in multisite environmentEPSS 0.3%CVE-2026-11458MEDIUMerzhongxmu JeeWMS Boot Actuator Endpoint actuator information disclosureEPSS 0.3%CVE-2026-96772MEDIUMIntelliants Subrion CMS actions.json assign-owner information disclosureEPSS 0.3%CVE-2024-44179LOWThis issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadEPSS 0.3%CVE-2024-54117MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.3%CVE-2026-61279MEDIUMVulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Proposals). Supported versions that are affected are 1EPSS 0.3%CVE-2026-104476HIGHBackdrop CMS before 1.35.1 Information Disclosure via Configuration Export ArchiveEPSS 0.3%CVE-2022-32913LOWThe issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7, macOS VeEPSS 0.3%CVE-2024-23224MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sEPSS 0.3%