Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-53887MEDIUMDirectus's exact version number is exposed by the OpenAPI SpecEPSS 0.9%CVE-2024-6555MEDIUMWP Popups – WordPress Popup builder <= 2.2.0.1 - Unauthenticated Full Path DisclosureEPSS 0.9%CVE-2025-62206MEDIUMMicrosoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-3508MEDIUMCertain HP DesignJet products – Information disclosureEPSS 0.9%CVE-2023-40275CRITICALAn issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstname= to _common/searchEPSS 0.9%CVE-2021-42523—There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c sepEPSS 0.9%CVE-2022-27614MEDIUMExposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remEPSS 0.9%CVE-2026-57205MEDIUMSimpleChat: Authenticated users can access other users' profile metadata through user IDOR endpointsEPSS 0.9%CVE-2025-53136MEDIUMNT OS Kernel Information Disclosure VulnerabilityEPSS 0.9%CVE-2022-40194MEDIUMWordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Sensitive Information Disclosure vulnerabilityEPSS 0.9%CVE-2023-50715MEDIUMUser accounts disclosed to unauthenticated actors on the LANEPSS 0.9%CVE-2017-20031LOWPHPList information disclosureEPSS 0.9%CVE-2022-39030HIGHSmart eVision - Exposure of Sensitive Information to an Unauthorized Actor -2EPSS 0.9%CVE-2022-25248MEDIUMPTC Axeda agent and Axeda Desktop Server Information ExposureEPSS 0.9%CVE-2022-30990—Sensitive information disclosure due to insecure folder permissionsEPSS 0.9%CVE-2023-0557HIGHContentStudio <= 1.2.5 - Information ExposureEPSS 0.9%CVE-2021-23890MEDIUMMcAfee ePO Information Leak vulnerabilityEPSS 0.9%CVE-2025-11079MEDIUMCampcodes Farm Management System file information disclosureEPSS 0.9%CVE-2022-22542—S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise SEPSS 0.9%CVE-2020-10274HIGHRVD#2556: MiR REST API allows for data exfiltration by unauthorized attackers (e.g. indoor maps)EPSS 0.9%