Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-49877MEDIUMIBM System Storage Virtualization Engine information disclosureEPSS 0.8%CVE-2023-34131—Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unauthenticated attacker EPSS 0.8%CVE-2023-3553MEDIUMExposure of Sensitive Information to an Unauthorized Actor in nilsteampassnet/teampassEPSS 0.8%CVE-2022-32218MEDIUMAn information disclosure vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to the actionLinkHandler method was found to alloEPSS 0.8%CVE-2020-1775LOWInformation disclosure in external interfaceEPSS 0.8%CVE-2025-9808MEDIUMThe Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information DisclosureEPSS 0.8%CVE-2023-23327MEDIUMAn Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are storEPSS 0.8%CVE-2021-41158MEDIUMFreeSWITCH vulnerable to SIP digest leak for configured gatewaysEPSS 0.8%CVE-2022-41935MEDIUMExposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-livetable-uiEPSS 0.8%CVE-2022-24742MEDIUMExposure of Sensitive Information Due to Incompatible Policies in SyliusEPSS 0.8%CVE-2023-23613MEDIUMField-level security issue with .keyword fields in OpenSearchEPSS 0.8%CVE-2020-7270MEDIUMSensitive Information Exposure in McAfee ATDEPSS 0.8%CVE-2019-25069MEDIUMAxios Italia Axios RE Error Message ASP.NET information disclosureEPSS 0.8%CVE-2023-3231LOWUJCMS ZIP Package information disclosureEPSS 0.8%CVE-2026-40895MEDIUMfollow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect TargetsEPSS 0.8%CVE-2025-47997MEDIUMMicrosoft SQL Server Information Disclosure VulnerabilityEPSS 0.8%CVE-2019-9541—Telos Automated Message Handling System information disclosure in itemlookup.aspEPSS 0.8%CVE-2022-22545—A high privileged user who has access to transaction SM59 can read connection details stored with the destination for http calls in SAP NetWEPSS 0.8%CVE-2023-52286HIGHTencent tdsqlpcloud through 1.8.5 allows unauthenticated remote attackers to discover database credentials via an index.php/api/install/get_EPSS 0.8%CVE-2022-22409MEDIUMIBM Aspera Faspex information disclosureEPSS 0.8%