Weaknesses of type CWE-200

4,979 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-22203MEDIUMwpDiscuz before 7.6.47 - Options Export Leaks OAuth Secrets in PlaintextEPSS 0.3%CVE-2024-52975CRITICALFleet Server sensitive information exposure via logsEPSS 0.3%CVE-2025-12147MEDIUMUnauthorized access to fields protected by Field-Level Security (FLS) when those fields are members of an objectEPSS 0.3%CVE-2024-25011MEDIUMEricsson Catalog Manager and Ericsson Order Care - Exposure of Sensitive Information VulnerabilityEPSS 0.3%CVE-2025-24283MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.EPSS 0.3%CVE-2020-8316MEDIUMA vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to read files on the sysEPSS 0.3%CVE-2025-12521MEDIUMAnalytify Pro <= 7.0.3 - Unauthenticated Information ExposureEPSS 0.3%CVE-2021-20259—A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attackeEPSS 0.3%CVE-2024-40850MEDIUMA file access issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macEPSS 0.3%CVE-2024-12575MEDIUMPoll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.8.9 - Unauthenticated Basic Information ExposureEPSS 0.3%CVE-2024-27814LOWThis issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical access to a device mEPSS 0.3%CVE-2026-12392MEDIUMRPC secret disclosure via vendor data endpoint in Canonical MAASEPSS 0.3%CVE-2026-41079MEDIUMOpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated usersEPSS 0.3%CVE-2025-6745MEDIUMWoodMart <= 8.2.5 - Unauthenticated Post DisclosureEPSS 0.3%CVE-2026-2128MEDIUMBreeze Cache <= 2.5.2 - Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login CookieEPSS 0.3%CVE-2022-32877MEDIUMA configuration issue was addressed with additional restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Monterey 12.6. An app mayEPSS 0.3%CVE-2026-55837MEDIUMdbt-mcp: Unauthenticated OAuth Context Endpoint Leaks dbt Platform TokensEPSS 0.3%CVE-2025-7368MEDIUMRehub <= 19.9.7 - Unauthenticated Password Protected Post DisclosureEPSS 0.3%CVE-2026-62998MEDIUMREDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column EnumerationEPSS 0.3%CVE-2022-32858MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. An app may be able to leaEPSS 0.3%