Weaknesses of type CWE-200

4,979 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-0553MEDIUMPossible to retrieve uncrypted firmware imageEPSS 0.3%CVE-2025-20379LOWRisky command safeguards bypass using the “/services/streams/search“ REST endpoint through “q“ parameter in Splunk EnterpriseEPSS 0.3%CVE-2026-61117MEDIUMVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.3%CVE-2026-86441LOWMISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidden Organisation DataEPSS 0.3%CVE-2026-100668HIGHGrav before 2.0.25 Sandbox Escape via array FilterEPSS 0.3%CVE-2026-18887MEDIUMIBM i is Affected By Sensitive Information Exposure Vulnerability in PASE []EPSS 0.3%CVE-2025-12540MEDIUMShareThis Dashboard for Google Analytics <= 3.2.4 - Unauthenticated Google Analytics Data ExposureEPSS 0.3%CVE-2023-24012HIGHData Distribution Service (DDS) Chain of Trust (CoT) violation vulnerability in Open DDSEPSS 0.3%CVE-2025-11794MEDIUMPassword hash and MFA secret returned in user email verification endpointEPSS 0.3%CVE-2025-24217MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15EPSS 0.3%CVE-2022-23546MEDIUMDiscourse vulnerable to private topic leak via email#send_digestEPSS 0.3%CVE-2026-86446LOWLearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-answer REST EndpointEPSS 0.3%CVE-2026-81348LOWMy Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds and SitemapEPSS 0.3%CVE-2026-55608MEDIUMn8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP modeEPSS 0.3%CVE-2022-41926LOWNextcloud Talk Android broadcast incorrect permission handlingEPSS 0.3%CVE-2024-48011LOWDell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A loEPSS 0.3%CVE-2025-29628CRITICALA Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home EPSS 0.3%CVE-2026-86407LOWUser Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Membership Thank You PageEPSS 0.3%CVE-2024-53858MEDIUMRecursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh cliEPSS 0.3%CVE-2026-69212MEDIUMHttp4s: FollowRedirect middleware leaks credentials over https->http same-authority redirectEPSS 0.3%