Weaknesses of type CWE-200

4,898 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2021-39327MEDIUMBulletProof Security <= 5.1 Sensitive Information DisclosureEPSS 71.7%CVE-2024-5010HIGHWhatsUp Gold TestController multiple information disclosure vulnerabilitiesEPSS 70.0%CVE-2023-50290MEDIUMApache Solr: Host environment variables are published via the Metrics APIEPSS 68.4%CVE-2024-0305MEDIUMGuangzhou Yingke Electronic Technology Ncast Guest Login IPSetup.php information disclosureEPSS 66.9%CVE-2024-42010HIGHmod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in renEPSS 66.7%CVE-2025-31125MEDIUMVite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` queryEPSS 64.7%KEVCVE-2016-0777MEDIUMThe resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitEPSS 63.5%CVE-2023-50968—Apache OFBiz: Arbitrary file properties reading and SSRF attackEPSS 63.4%CVE-2023-50720MEDIUMXWiki Platform Solr search discloses email addresses of usersEPSS 59.1%CVE-2021-32819HIGHRemote code execution in squirrellyEPSS 58.3%CVE-2023-28770HIGHThe sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior toEPSS 57.8%CVE-2012-6441—Rockwell Automation ControlLogix PLC Information ExposureEPSS 57.1%CVE-2024-45388HIGHArbitrary file read in the `/api/v2/simulation` endpoint in hoverfly (`GHSL-2023-274`)EPSS 55.6%CVE-2024-31817HIGHIn TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatEPSS 55.3%CVE-2020-12027MEDIUMRockwell Automation FactoryTalk View SEEPSS 53.0%CVE-2016-2388MEDIUMThe Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a craftedEPSS 52.2%KEVCVE-2024-38030MEDIUMWindows Themes Spoofing VulnerabilityEPSS 51.1%CVE-2018-5430HIGHTIBCO JasperReports Server Information Disclosure VulnerabilityEPSS 49.6%KEVCVE-2024-46938HIGHAn issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release throEPSS 46.8%CVE-2023-4168MEDIUMTemplatecookie Adlisting Redirect ad-list information disclosureEPSS 46.0%