Weaknesses of type CWE-200

4,985 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-19439HIGHUltimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Customer PII Disclosure via wps_uwgc_report_detailsEPSS 0.3%CVE-2025-61639LOWSuppressed blocked IP is visible in Special:BlockList, RC, and other placesEPSS 0.3%CVE-2022-39043LOWJuiker app - Information LeakageEPSS 0.3%CVE-2026-100687HIGHBudibase Server before 3.45.0 Credential Exposure via External Table BroadcastEPSS 0.3%CVE-2024-31799MEDIUMInformation Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via thEPSS 0.3%CVE-2025-24262MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.4. A sandboxed aEPSS 0.3%CVE-2026-16405HIGHInformation disclosure in the Networking: WebSockets componentEPSS 0.3%CVE-2025-12677MEDIUMKiotViet Sync <= 1.8.5 - Unauthenticated Webhook Key ExposureEPSS 0.3%CVE-2026-100244HIGHCentralAuth exposes locally suppressed block information via globaluserinfo API and Special:CentralAuth (incomplete fix for CVE-2025-62669)EPSS 0.3%CVE-2025-12141LOWGrafana Alerting Editors can edit destination of webhooks they did not createEPSS 0.3%CVE-2024-23104MEDIUMAn exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNEPSS 0.3%CVE-2025-20377MEDIUMCisco Unified Intelligence Center API Information Disclosure VulnerabilityEPSS 0.3%CVE-2022-32849MEDIUMAn information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big SuEPSS 0.3%CVE-2025-13215MEDIUMShortcodes and extra features for Phlox theme <= 2.17.13 - Unauthenticated Draft Posts Information ExposureEPSS 0.3%CVE-2024-4220MEDIUMInformation Disclosure in BeyondInsightEPSS 0.3%CVE-2025-61164HIGHCohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.EPSS 0.3%CVE-2025-12098MEDIUMAcademy LMS Pro <= 3.3.8 - Unauthenticated Sensitive Information Exposure via 'enqueue_social_login_script'EPSS 0.3%CVE-2025-12584MEDIUMQuick View for WooCommerce <= 2.2.17 - Unauthenticated Private Product DisclosureEPSS 0.3%CVE-2025-24280MEDIUMAn access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app mEPSS 0.3%CVE-2024-23236MEDIUMA correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary filesEPSS 0.3%