Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2021-44172LOWAn exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 EPSS 0.9%CVE-2021-33727—A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profiEPSS 0.9%CVE-2024-38650CRITICALAn authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.EPSS 0.9%CVE-2026-25475MEDIUMOpenClaw Vulnerable to Local File Inclusion via MEDIA: Path ExtractionEPSS 0.9%CVE-2023-0027MEDIUMRockwell Automation Modbus TCP AOI Server Could Leak Sensitive InformationEPSS 0.8%CVE-2022-31143MEDIUMLeak of sensitive information through login page error in GLPIEPSS 0.8%CVE-2023-24923MEDIUMMicrosoft OneDrive for Android Information Disclosure VulnerabilityEPSS 0.8%CVE-2024-45791HIGHApache HertzBeat: Exposure sensitive token via http GET method with query stringEPSS 0.8%CVE-2022-4415MEDIUMA vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suEPSS 0.8%CVE-2024-39676HIGHApache Pinot: Unauthorized endpoint exposed sensitive informationEPSS 0.8%CVE-2021-37703MEDIUMInformation exposure in DiscourseEPSS 0.8%CVE-2024-28442HIGHDirectory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via tEPSS 0.8%CVE-2023-5256HIGHDrupal core - Critical - Cache poisoning - SA-CORE-2023-006EPSS 0.8%CVE-2025-34185HIGHIlevia EVE X1 Server 4.7.18.0.eden Unauthenticated File DisclosureEPSS 0.8%CVE-2023-2446MEDIUMUserPro <= 5.1.1 - Sensitive Information Disclosure via ShortcodeEPSS 0.8%CVE-2021-32750MEDIUMDe-anonymization via messageEPSS 0.8%CVE-2023-5692MEDIUMWordPress Core <= 6.4.3 - Sensitive Information Exposure via redirect_guess_404_permalinkEPSS 0.8%CVE-2020-1777MEDIUMAgent names disclosed in chat featureEPSS 0.8%CVE-2021-31371MEDIUMJunos OS: QFX5000 Series: Traffic from the network internal to the device (128.0.0.0) may be forwarded to egress interfaces.EPSS 0.8%CVE-2024-39210HIGHBest House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php.EPSS 0.8%