Weaknesses of type CWE-200

5,017 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-53011HIGHPermissions, Privileges, and Access Controls in Video Analytics and ProcessingEPSS 0.1%CVE-2026-81322LOWCloaked plaintext leaks through a non-sensitive action argument in AshCloakEPSS 0.1%CVE-2025-71280MEDIUMXenForo Local Account Page Caching Information DisclosureEPSS 0.1%CVE-2024-27277MEDIUMIBM Storage Protect Plus Server information disclosureEPSS 0.1%CVE-2026-20730LOWBIG-IP Edge Client for Windows vulnerabilityEPSS 0.1%CVE-2022-42782MEDIUMIn wlan driver, there is a possible missing permission check, This could lead to local information disclosure.EPSS 0.1%CVE-2017-18306HIGHInformation Exposure in Camera DriverEPSS 0.1%CVE-2023-25536MEDIUM Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user couEPSS 0.1%CVE-2017-18307HIGHInformation Exposure in KernelEPSS 0.1%CVE-2022-39913MEDIUMExposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user prEPSS 0.1%CVE-2022-40525HIGHInformation Exposure in Linux Networking FirmwareEPSS 0.1%CVE-2022-42766MEDIUMIn wlan driver, there is a possible missing permission check, This could lead to local information disclosure.EPSS 0.1%CVE-2023-21624MEDIUMInformation Exposure in DSP ServicesEPSS 0.1%CVE-2022-40523HIGHInformation exposure in KernelEPSS 0.1%CVE-2024-43046MEDIUMInformation Exposure in TZ Secure OSEPSS 0.1%CVE-2024-5464MEDIUMVulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affecEPSS 0.1%CVE-2026-43942MEDIUMelecterm: Full process.env exposed to renderer via window.pre.env in electermEPSS 0.1%CVE-2026-58554MEDIUMPermission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiEPSS 0.1%CVE-2023-21267—In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic errorEPSS 0.1%CVE-2025-68467LOWDark Reader gives users the ability to request style sheets from local web serversEPSS 0.1%