Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-24250CRITICALThis issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13EPSS 0.9%CVE-2025-24246CRITICALAn injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.EPSS 0.9%CVE-2019-17321—ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, couldEPSS 0.9%CVE-2022-24890LOWExposure of Private Personal Information to an Unauthorized Actor in Nextcloud TalkEPSS 0.9%CVE-2017-16007—node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based serversEPSS 0.9%CVE-2024-1200MEDIUMJspxcms information disclosureEPSS 0.9%CVE-2021-21587MEDIUMDell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A local unauthenticated attacker could expEPSS 0.9%CVE-2024-38017MEDIUMMicrosoft Message Queuing Information Disclosure VulnerabilityEPSS 0.9%CVE-2021-22749—A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prEPSS 0.9%CVE-2022-23711—A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack moEPSS 0.9%CVE-2026-65769MEDIUMMicrosoft Teams iOS Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-50508MEDIUMWindows NTLM Spoofing VulnerabilityEPSS 0.9%CVE-2020-5301LOWInformation disclosure of source code in SimpleSAMLphpEPSS 0.9%CVE-2026-56646MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.9%CVE-2026-47284MEDIUMVisual Studio Code Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-27736MEDIUMWindows Power Dependency Coordinator Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-61924MEDIUMWindows Remote Desktop Client Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-61921MEDIUMWindows Remote Desktop Client Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-61918MEDIUMWindows Remote Desktop Client Information Disclosure VulnerabilityEPSS 0.9%CVE-2024-23206MEDIUMAn access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 EPSS 0.9%