Weaknesses of type CWE-200

4,898 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-31133HIGHGhost vulnerable to disclosure of private API fieldsEPSS 45.7%CVE-2019-3993—ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's EPSS 45.7%CVE-2024-6646MEDIUMNetgear WN604 Web Interface downloadFile.php information disclosureEPSS 45.7%CVE-2025-31486MEDIUMVite allows server.fs.deny to be bypassed with .svg or relative pathsEPSS 40.5%CVE-2022-45354MEDIUMWordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data ExposureEPSS 38.1%CVE-2008-0655HIGHMultiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.EPSS 37.9%KEVCVE-2022-22733—Access-Token in ElasticJob UI causes password disclosureEPSS 37.6%CVE-2020-7387MEDIUMSage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized ActorEPSS 36.4%CVE-2025-52488HIGHDNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user inputEPSS 35.8%CVE-2023-41323MEDIUMUsers login enumeration by unauthenticated user in GLPIEPSS 33.9%CVE-2024-3274MEDIUMD-Link DNS-320L/DNS-320LW/DNS-327L HTTP GET Request info.cgi information disclosureEPSS 33.5%CVE-2021-21816MEDIUMAn information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request cEPSS 32.4%CVE-2023-39677—MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information discloEPSS 32.3%CVE-1999-0524MEDIUMICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.EPSS 32.2%CVE-2024-7339MEDIUMTVT DVR TD-2104TS-CL queryDevInfo information disclosureEPSS 32.0%CVE-2026-20133MEDIUMA vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affectEPSS 31.8%KEVCVE-2025-50154MEDIUMMicrosoft Windows File Explorer Spoofing VulnerabilityEPSS 30.2%CVE-2024-53991HIGHPotential Backup file leaked via Nginx in DiscourseEPSS 29.9%CVE-2025-68686MEDIUMAn Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,EPSS 29.6%KEVCVE-2021-38314MEDIUMGutenberg Template Library & Redux Framework <= 4.2.11 Sensitive Information DisclosureEPSS 29.0%