Weaknesses of type CWE-200

4,909 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2020-36723MEDIUMListingPro - WordPress Directory & Listing Theme < 2.6.1 - Sensitive Information DisclosureEPSS 1.6%CVE-1999-0059HIGHIRIX fam service allows an attacker to obtain a list of all files on the server.EPSS 1.6%CVE-2018-16870—It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLSEPSS 1.6%CVE-2020-1757HIGHA flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to unEPSS 1.6%CVE-2021-21564CRITICALDell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may pEPSS 1.6%CVE-2003-20001MEDIUMAn issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an eEPSS 1.6%CVE-2025-25037CRITICALAquatronica Controller System Complete Information DisclosureEPSS 1.6%CVE-2019-5470—An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could resulEPSS 1.6%CVE-2026-30928HIGHGlances Exposes Unauthenticated Configuration SecretsEPSS 1.6%CVE-2018-12130MEDIUMMicroarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authEPSS 1.6%CVE-2019-12704MEDIUMCisco SPA100 Series Analog Telephone Adapters Web-Based Management Interface File Disclosure VulnerabilityEPSS 1.6%CVE-2023-50298HIGHApache Solr: Solr can expose ZooKeeper credentials via Streaming ExpressionsEPSS 1.6%CVE-2021-4076—A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.EPSS 1.6%CVE-2020-6993—In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, an attacker can gain access to senEPSS 1.6%CVE-2018-0140—A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authEPSS 1.6%CVE-2021-32028—A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database EPSS 1.6%CVE-2023-42663—Apache Airflow: Bypass permission verification to view task instances of other dagsEPSS 1.6%CVE-2021-21360MEDIUMExposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetupEPSS 1.5%CVE-2022-40629HIGHSensitive Information Disclosure Vulnerability in Tacitine FirewallEPSS 1.5%CVE-2021-41120HIGHUnauthorized access to Credit card form in sylius/paypal-pluginEPSS 1.5%