Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-42878MEDIUMFacturaScripts: Unauthenticated phpinfo() Disclosure via Installer Endpoint in FacturaScriptsEPSS 0.9%CVE-2021-25110—Futurio Extra < 1.6.3 - Subscriber+ User Email Address DisclosureEPSS 0.9%CVE-2021-33709—A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versionEPSS 0.9%CVE-2023-43796MEDIUMSynapse vulnerable to leak of remote user device informationEPSS 0.9%CVE-2021-39163LOWAdding a private/unlisted room to a community exposes room metadata in an unauthorised manner.EPSS 0.9%CVE-2017-15138MEDIUMThe OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidentiaEPSS 0.9%CVE-2022-31190MEDIUMMetadata of withdrawn Items is exposed to anonymous users in DSpace XMLUIEPSS 0.9%CVE-2023-26476HIGHTwo XWiki Platform UIs Expose Sensitive Information to an Unauthorized ActorEPSS 0.9%CVE-2026-21532HIGHAzure Function Information Disclosure VulnerabilityEPSS 0.9%CVE-2017-12310—A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sEPSS 0.9%CVE-2023-6101MEDIUMMaiwei Safety Production Control Platform Intelligent Monitoring ha.html information disclosureEPSS 0.9%CVE-2022-27633MEDIUMAn information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specEPSS 0.9%CVE-2022-31134MEDIUMZulip Server public data export contains attachments that are non-publicEPSS 0.9%CVE-2022-27630MEDIUMAn information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A spEPSS 0.9%CVE-2022-31162HIGHSlack Morphism for Rust before 0.41.0 can accidentally leak Slack OAuth client information in application debug logsEPSS 0.9%CVE-2024-23321HIGHApache RocketMQ: Unauthorized Exposure of Sensitive DataEPSS 0.9%CVE-2021-24164—Ninja Forms < 3.4.34.1 - Authenticated OAuth Connection Key DisclosureEPSS 0.9%CVE-2023-7094MEDIUMNetentsec NS-ASG Application Security Gateway nsasg6.0.tgz information disclosureEPSS 0.9%CVE-2025-59716MEDIUMownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insEPSS 0.9%CVE-2013-10007MEDIUMethitter WP-Print-Friendly wp-print-friendly.php information disclosureEPSS 0.9%