Weaknesses of type CWE-200

4,989 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2021-21534MEDIUMDell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vuEPSS 0.2%CVE-2026-11424HIGHServer-Side Request Forgery in Altium Platform Design GraphQL Service Allows Information DisclosureEPSS 0.2%CVE-2026-1307MEDIUMNinja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor TokenEPSS 0.2%CVE-2024-24891MEDIUMInformation Leakage in kernelEPSS 0.2%CVE-2025-55272LOWHCL Aftermarket DPC is affected by Banner Disclosure vulnerabilityEPSS 0.2%CVE-2024-24898MEDIUMInformation Leakage in kernelEPSS 0.2%CVE-2022-32824—The issue was addressed with improved memory handling. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may bEPSS 0.2%CVE-2025-54548MEDIUMOn affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user password hashes)EPSS 0.2%CVE-2025-64324HIGHKubeVirt Vulnerable to Arbitrary Host File Read and WriteEPSS 0.2%CVE-2026-79147MEDIUMInformation leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potenEPSS 0.2%CVE-2022-33181MEDIUMAn information disclosure vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could aEPSS 0.2%CVE-2023-22307MEDIUMSite-Passwords in GET parametersEPSS 0.2%CVE-2024-54119MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2025-6461MEDIUMCubeWP – All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.phpEPSS 0.2%CVE-2024-32754LOWJohnson Controls Kantech KT1, KT2, and KT400 Door Controllers - Exposure of Sensitive InformationEPSS 0.2%CVE-2026-94185MEDIUMnvm alias resolution follows `..` and discloses files outside $NVM_DIR/aliasEPSS 0.2%CVE-2026-1867MEDIUMWP Front User Submit < 5.0.6 - Unauthenticated Sensitive Information ExposureEPSS 0.2%CVE-2026-67448MEDIUMMailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)EPSS 0.2%CVE-2021-36341MEDIUMDell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated user with low priviEPSS 0.2%CVE-2025-25370MEDIUMAn issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain sensitive informatiEPSS 0.2%