Weaknesses of type CWE-200

4,909 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2020-8210—Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile SEPSS 1.5%CVE-2025-6082MEDIUMBirth Chart Compatibility <= 2.0 - Unauthenticated Full Path ExposureEPSS 1.5%CVE-2023-38344—An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP actioEPSS 1.5%CVE-2018-10857MEDIUMgit-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annEPSS 1.5%CVE-2016-9159MEDIUMA vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPEPSS 1.5%CVE-2026-2025HIGHMail Mint < 1.19.5 - Unauthenticated Emails DisclosureEPSS 1.5%CVE-2020-35518—When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be usedEPSS 1.5%CVE-2019-13410—TOPMeeting version before version 8.8 (2019/08/19) allows an attacker to obtain sensitive informationEPSS 1.5%CVE-2023-35005—Apache Airflow: Information disclosure on configuration viewEPSS 1.5%CVE-2025-29805HIGHOutlook for Android Information Disclosure VulnerabilityEPSS 1.5%CVE-2022-31091HIGHChange in port should be considered a change in origin in GuzzleEPSS 1.5%CVE-2017-12224—A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remoEPSS 1.5%CVE-2022-34708MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 1.5%CVE-2026-13153HIGHEssential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products EndpointEPSS 1.5%CVE-2022-34710MEDIUMWindows Defender Credential Guard Information Disclosure VulnerabilityEPSS 1.5%CVE-2022-34712MEDIUMWindows Defender Credential Guard Information Disclosure VulnerabilityEPSS 1.5%CVE-2021-3714—A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication can be attacked via EPSS 1.5%CVE-2018-16849LOWA flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presenceEPSS 1.5%CVE-2019-1010299—The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of unEPSS 1.5%CVE-2018-12126MEDIUMMicroarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an auEPSS 1.5%