Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2017-20007MEDIUMInformation Exposure in INGEPAC DA AUEPSS 1.1%CVE-2025-55243HIGHMicrosoft OfficePlus Spoofing VulnerabilityEPSS 1.1%CVE-2021-21400HIGHEntering code in App Lock modal sends input to conversationEPSS 1.1%CVE-2025-1595MEDIUMAnhui Xufan Information Technology EasyCVR getbaseconfig information disclosureEPSS 1.1%CVE-2022-31176HIGHGrafana Image Renderer leaking filesEPSS 1.1%CVE-2021-32716MEDIUMInternal hidden fields are visible on to many associations in admin apiEPSS 1.1%CVE-2021-22134—A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. EPSS 1.1%CVE-2016-9590MEDIUMpuppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation oEPSS 1.1%CVE-2022-27863MEDIUMWordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 - Sensitive Data Exposure vulnerabilityEPSS 1.1%CVE-2021-22137—In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. SearcEPSS 1.1%CVE-2022-23984LOWWordPress wpDiscuz plugin <= 7.3.11 - Sensitive Information DisclosureEPSS 1.1%CVE-2020-3193MEDIUMCisco Prime Collaboration Provisioning Information Disclosure VulnerabilityEPSS 1.1%CVE-2017-0881—An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server beforEPSS 1.1%CVE-2021-0210MEDIUMJunos OS: Privilege escalation in J-Web due to arbitrary command and code execution via information disclosure from another users active sessionEPSS 1.1%CVE-2021-43938HIGHElcomplus SmartPTT SCADA Server Information ExposureEPSS 1.1%CVE-2023-24838CRITICALHGiga PowerStation - Information LeakageEPSS 1.1%CVE-2021-22044—In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@ReEPSS 1.1%CVE-2025-24232CRITICALThis issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13EPSS 1.1%CVE-2025-43362CRITICALThe issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An app may be able to mEPSS 1.1%CVE-2022-24747MEDIUMHTTP caching is marking private HTTP headers as publicEPSS 1.1%