Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2018-11728MEDIUMThe libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attaEPSS 1.2%CVE-2023-28271MEDIUMWindows Kernel Memory Information Disclosure VulnerabilityEPSS 1.2%CVE-2021-22135—Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API EPSS 1.2%CVE-2026-26273CRITICALKnown affected by Account Takeover via Password Reset Token LeakageEPSS 1.2%CVE-2025-47966CRITICALPower Automate Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2021-31381MEDIUMSRC Series: A remote attacker sending a specially crafted query may cause the web server to delete filesEPSS 1.2%CVE-2024-30472HIGHTelemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with loEPSS 1.2%CVE-2019-13557—In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker tEPSS 1.2%CVE-2024-9821HIGHBot for Telegram on WooCommerce <= 1.2.7 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication BypassEPSS 1.2%CVE-2007-3650MEDIUMmyWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached EPSS 1.2%CVE-2025-34130HIGHLILIN DVR Arbitrary File Read via net_html.cgiEPSS 1.1%CVE-2024-1098MEDIUMRebuild proxy-download QiniuCloud.getStorageFile information disclosureEPSS 1.1%CVE-2021-32707MEDIUMBypass of image blocking in Nextcloud MailEPSS 1.1%CVE-2022-22680MEDIUMExposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42EPSS 1.1%CVE-2022-31139MEDIUMNo security checking for UnsafeAccess.getInstance() in UnsafeAccessorEPSS 1.1%CVE-2017-20101LOWProjectSend information disclosureEPSS 1.1%CVE-2019-11282MEDIUMUAA is vulnerable to a Blind SCIM injection leading to information disclosureEPSS 1.1%CVE-2017-2654LOWjenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dyEPSS 1.1%CVE-2021-31380MEDIUMSRC Series: A remote attacker sending a specially crafted query may cause the web server to disclose sensitive informationEPSS 1.1%CVE-2024-21147HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: HotspotEPSS 1.1%