Weaknesses of type CWE-200

4,979 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-11644LOWTomofun Furbo 360/Furbo Mini UART sensitive informationEPSS 0.3%CVE-2024-49734HIGHIn multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to tEPSS 0.3%CVE-2025-68436MEDIUMCraft CMS vulnerable to potential information disclosure via unchecked asset relocationEPSS 0.3%CVE-2024-53858MEDIUMRecursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh cliEPSS 0.3%CVE-2026-69212MEDIUMHttp4s: FollowRedirect middleware leaks credentials over https->http same-authority redirectEPSS 0.3%CVE-2020-25836MEDIUMPotential information leakage resulting in unauthorized accessEPSS 0.3%CVE-2026-35140LOWHCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerabilityEPSS 0.3%CVE-2026-0411MEDIUMA Sensitive Information Disclosure Vulnerability in NETGEAR Orbi SatellitesEPSS 0.3%CVE-2025-11151HIGHInformation Disclosure in Beyaz Computer's CityPLusEPSS 0.3%CVE-2023-5551LOWMoodle: forum summary report shows students from other groups when in separate groups modeEPSS 0.3%CVE-2022-42815MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitiveEPSS 0.3%CVE-2026-39372MEDIUMInvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in AttachmentsEPSS 0.3%CVE-2024-32051MEDIUMInsertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a networkEPSS 0.3%CVE-2026-67406MEDIUMRabbitMQ: Federation and Shovel Gen-Servers Lack format_status Callback — Plaintext Credentials Exposed in Crash Dumps and sys:get_statusEPSS 0.3%CVE-2026-76692HIGHUnauthenticated Adjacent Information Disclosure and Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.3%CVE-2025-31207HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to enumerate a user's EPSS 0.3%CVE-2026-12111MEDIUMAppointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' ParameterEPSS 0.3%CVE-2026-24487MEDIUMOpenEMR has FHIR Patient Compartment Bypass in CareTeam ResourceEPSS 0.3%CVE-2026-82385MEDIUMApache Roller: Weblog template include escapes the Velocity sandbox and reads classpath filesEPSS 0.3%CVE-2025-30443MEDIUMA privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sequoia 15.5, macOS Sonoma 1EPSS 0.3%