Weaknesses of type CWE-200

4,979 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-40823MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app EPSS 0.3%CVE-2025-52669MEDIUMInsecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to havEPSS 0.3%CVE-2022-32913LOWThe issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7, macOS VeEPSS 0.3%CVE-2026-60705HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.3%CVE-2026-100671HIGHGrav before 2.0.25 Session Cookie Theft via Twig SandboxEPSS 0.3%CVE-2022-22506MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.3%CVE-2024-45250MEDIUMZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2024-58255MEDIUMEnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.EPSS 0.3%CVE-2025-49824LOWconda-smithy Insecure Encryption Vulnerable to Oracle Padding AttackEPSS 0.3%CVE-2026-84464HIGHZammad: IDOR in External Data Source rendering exposes ticket, user, group, and organization dataEPSS 0.3%CVE-2024-42338MEDIUMCyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2024-42339MEDIUMCyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2025-31955HIGHHCL iAutomate is affected by a sensitive data exposure vulnerabilityEPSS 0.3%CVE-2021-0170MEDIUMExposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systemsEPSS 0.3%CVE-2025-46382MEDIUMCWE-200 Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2026-27949LOWPlane Exposes User Email (PII and part of credential) in GET ParameterEPSS 0.3%CVE-2025-53092MEDIUMStrapi core vulnerable to sensitive data exposure via CORS misconfigurationEPSS 0.3%CVE-2026-56584LOWHCL IEM was affected with the Information disclosure nginx serverEPSS 0.3%CVE-2025-54786MEDIUMSuiteCRM: Legacy iCal service allows unauthenticated access to meeting dataEPSS 0.3%CVE-2025-24164MEDIUMA logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An aEPSS 0.3%