Weaknesses of type CWE-200

4,992 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-3780HIGHInformation exposure vulnerability on Technicolor CGA2121EPSS 0.2%CVE-2025-31256MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.5. Hot corner may unexpectedly reveal a usEPSS 0.2%CVE-2025-65104HIGHFirebird: Information leak vulnerability in firebird3 client when used with newer serverEPSS 0.2%CVE-2025-20030LOWExposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow aEPSS 0.2%CVE-2026-22051LOWStorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerabiliEPSS 0.2%CVE-2025-11998MEDIUMHP Card Readers (B Models) – Potential Information DisclosureEPSS 0.2%CVE-2022-42442LOWIBM Robotic Process Automation for Cloud Pak information disclosureEPSS 0.2%CVE-2026-49988MEDIUMRepomix: attach_packed_output can bypass file-read secret scanning for supported local filesEPSS 0.2%CVE-2024-29720MEDIUMAn issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt componentEPSS 0.2%CVE-2025-31231MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read sensitEPSS 0.2%CVE-2022-20591MEDIUMIn ppmpu_set of ppmpu.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information dEPSS 0.2%CVE-2024-2371MEDIUMInformation exposure vulnerability in Korenix JetI/O 6550EPSS 0.2%CVE-2024-45450MEDIUMPermission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.2%CVE-2023-38300MEDIUMA certain software build for the Orbic Maui device (Orbic/RC545L/RC545L:10/ORB545L_V1.4.2_BVZPP/230106:user/release-keys) leaks the IMEI andEPSS 0.2%CVE-2026-47395MEDIUMPraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model contextEPSS 0.2%CVE-2026-16592LOWWP Directory Kit <= 1.5.7 - Contributor+ Non-Public Listing Field Disclosure via ShortcodesEPSS 0.2%CVE-2022-46646LOWExposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated user to potentially enaEPSS 0.2%CVE-2025-57839MEDIUMPhoto module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentialityEPSS 0.2%CVE-2025-57838MEDIUMSome Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confideEPSS 0.2%CVE-2022-31221LOWDell BIOS versions contain an Information Exposure vulnerability. A local authenticated administrator user could potentially exploit this vuEPSS 0.2%