Weaknesses of type CWE-200

4,909 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2018-12127MEDIUMMicroarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authentiEPSS 1.5%CVE-2025-24011MEDIUMUmbraco CMS Vulnerable to User Enumeration Feasible Based On Management API Timing and Response CodesEPSS 1.5%CVE-2023-1387MEDIUMGrafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to searcEPSS 1.5%CVE-2024-10916MEDIUMD-Link DNS-320/DNS-320LW/DNS-325/DNS-340L HTTP GET Request info.xml information disclosureEPSS 1.5%CVE-2021-32029—A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read EPSS 1.5%CVE-2023-24881MEDIUMMicrosoft Teams Information Disclosure VulnerabilityEPSS 1.5%CVE-2022-27844LOWWordPress WPvivid plugin <= 0.9.70 - Arbitrary File Read vulnerabilityEPSS 1.5%CVE-2018-10852LOWThe UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone EPSS 1.5%CVE-2021-21336MEDIUMExposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManagerEPSS 1.5%CVE-2008-3893MEDIUMMicrosoft Bitlocker in Windows Vista before SP1 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear thisEPSS 1.5%CVE-2022-47184HIGHApache Traffic Server: The TRACE method can be use to disclose network informationEPSS 1.5%CVE-2023-33933HIGHApache Traffic Server: s3_auth plugin problem with hash calculationEPSS 1.5%CVE-2018-0474MEDIUMCisco Unified Communications Manager Digest Credentials Disclosure VulnerabilityEPSS 1.5%CVE-2026-52815MEDIUMGogs: Unauthenticated Organization Teams Information Disclosure via APIEPSS 1.5%CVE-2018-13288MEDIUMInformation exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remoteEPSS 1.5%CVE-2018-13297MEDIUMInformation exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitEPSS 1.5%CVE-2018-0218—A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticateEPSS 1.5%CVE-2017-11510—An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator usEPSS 1.5%CVE-2018-0207—A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticateEPSS 1.5%CVE-2018-0187MEDIUMCisco Identity Services Engine Privileged Account Sensitive Information Disclosure VulnerabilityEPSS 1.5%