Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-43959MEDIUMInsufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to EPSS 1.0%CVE-2022-35715MEDIUMIBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error messageEPSS 1.0%CVE-2025-10093MEDIUMD-Link DIR-852 Device Configuration getcfg.php phpcgi_main information disclosureEPSS 1.0%CVE-2010-1432—Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may EPSS 1.0%CVE-2022-20648MEDIUMCisco Redundancy Configuration Manager Debug Information Disclosure VulnerabilityEPSS 1.0%CVE-2026-25185MEDIUMWindows Shell Link Processing Spoofing VulnerabilityEPSS 1.0%CVE-2023-29517HIGHExposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-office-viewerEPSS 1.0%CVE-2023-47668MEDIUMWordPress Restrict Content Plugin <= 3.2.7 is vulnerable to Sensitive Data ExposureEPSS 1.0%CVE-2018-15432—Cisco Prime Infrastructure Information Disclosure VulnerabilityEPSS 1.0%CVE-2018-15433—Cisco Prime Infrastructure Information Disclosure VulnerabilityEPSS 1.0%CVE-2024-5483MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON APIEPSS 1.0%CVE-2019-11268MEDIUMUAA SQL Identity Zone VulnerabilityEPSS 1.0%CVE-2022-0384—Video Conferencing with Zoom < 3.8.17 - E-mail Address DisclosureEPSS 1.0%CVE-2022-23469LOWAuthorization header displayed in the debug logsEPSS 1.0%CVE-2025-9196MEDIUMTrinity Audio <= 5.21.0 - Unauthenticated Information ExposureEPSS 1.0%CVE-2019-3868LOWKeycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIEPSS 1.0%CVE-2020-1779MEDIUMDynamic templates reveal sensitive data when OTRS tags are usedEPSS 1.0%CVE-2025-64670MEDIUMWindows DirectX Information Disclosure VulnerabilityEPSS 1.0%CVE-2020-36319LOWPotential sensitive data exposure in applications using Vaadin 15EPSS 1.0%CVE-2021-32689HIGHNextcloud Talk not properly disassociating users from chats after account deletionEPSS 1.0%