Weaknesses of type CWE-200

4,991 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-25823LOWInformation Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in lEPSS 0.2%CVE-2022-25829LOWInformation Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information oEPSS 0.2%CVE-2026-2317MEDIUMInappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a EPSS 0.2%CVE-2026-100851HIGHAzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/profileEPSS 0.2%CVE-2022-25830LOWInformation Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information oEPSS 0.2%CVE-2022-25826LOWInformation Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access password information of coEPSS 0.2%CVE-2026-57449HIGHActual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub TokenEPSS 0.2%CVE-2026-88929MEDIUMSale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product DisclosureEPSS 0.2%CVE-2026-17517MEDIUMContent Views < 4.5.1.2 - Unauthenticated Non-Public Post Content Disclosure via Views Status FilterEPSS 0.2%CVE-2026-90988MEDIUMRequest a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenumEPSS 0.2%CVE-2026-92995MEDIUMVerge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_fileEPSS 0.2%CVE-2026-90985MEDIUMWPC Smart Compare for WooCommerce < 6.6.1 - Unauthenticated Password-Protected Product Description Disclosure via woosc_loadEPSS 0.2%CVE-2026-96886MEDIUMCourse Booking System < 7.0.9 - Unauthenticated Attendee PII Disclosure via CSV ExportEPSS 0.2%CVE-2026-18232MEDIUMWP Directory Kit <= 1.5.7 - Unauthenticated Unpublished Listing Disclosure via map_infowindowEPSS 0.2%CVE-2025-13821MEDIUMUser profile update exposes password hash and MFA secretsEPSS 0.2%CVE-2026-14562MEDIUMTeddy Bear Customize Addon <= 1.0.5 - Unauthenticated Order Data DisclosureEPSS 0.2%CVE-2026-11871MEDIUMTeam Showcase Supreme < 9.3 - Unauthenticated Sensitive Data Disclosure via wpm_6310_team_member_detailsEPSS 0.2%CVE-2026-86783MEDIUMPostX < 5.0.41 - Unauthenticated Custom Field Key Disclosure via REST APIEPSS 0.2%CVE-2025-43509MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. EPSS 0.2%CVE-2026-86789MEDIUMConnections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST RoutesEPSS 0.2%