Weaknesses of type CWE-200

4,985 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-37939LOWAn exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.EPSS 0.2%CVE-2025-65278HIGHAn issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive iEPSS 0.2%CVE-2023-23776MEDIUMAn exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiAnalyzer versions 7.2.0 through 7.2.1, 7.0.0 tEPSS 0.2%CVE-2026-100594HIGHOpenClaw before 2026.7.1 Authorization Bypass via trajectory exportEPSS 0.2%CVE-2026-80333MEDIUMSolace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview RoutesEPSS 0.2%CVE-2026-78941LOWInformation leak in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypasEPSS 0.2%CVE-2026-67171MEDIUMHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2022-46702MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to disclose kerneEPSS 0.2%CVE-2026-14062MEDIUMInappropriate implementation in Views in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed an attacker who convinced a user to instalEPSS 0.2%CVE-2026-67106MEDIUMHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2026-16966MEDIUMSolace Extra < 1.7.0 - Unauthenticated Draft/Private Site Builder Content Disclosure via get_elementor_contentEPSS 0.2%CVE-2024-44158MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.7 and iPadOS 17.7, macOS Sequoia 15EPSS 0.2%CVE-2026-100725HIGHhttp4k before 6.48.0.0 Cookie Scoping Bypass via BasicCookieStorageEPSS 0.2%CVE-2026-87658MEDIUMInformation leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain croEPSS 0.2%CVE-2026-87461MEDIUMInformation leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted Chrome exEPSS 0.2%CVE-2021-25350LOWInformation Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user informaEPSS 0.2%CVE-2024-1460MEDIUMMSI Afterburner v4.6.5.16370 - Kernel Memory LeakEPSS 0.2%CVE-2022-23509HIGHWeave Gitops Run vulnerable to insecure communicationEPSS 0.2%CVE-2025-30451MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. An app may be able to EPSS 0.2%CVE-2026-76089HIGHFormie: Missing authorization on sent notification resend modal exposes submission PIIEPSS 0.2%