Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-57102HIGHVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2025-58739MEDIUMMicrosoft Windows File Explorer Spoofing VulnerabilityEPSS 0.8%CVE-2021-22739—Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a device to be compromEPSS 0.8%CVE-2022-25948MEDIUMInformation ExposureEPSS 0.8%CVE-2021-21443LOWUnautorized listing of the customer user emailsEPSS 0.8%CVE-2024-43779HIGHAn information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted EPSS 0.8%CVE-2024-47868MEDIUMSeveral components’ post-process steps may allow arbitrary file leaks in GradioEPSS 0.8%CVE-2019-15594—GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request eEPSS 0.8%CVE-2023-44312MEDIUMApache ServiceComb Service-Center: attacker can query all environment variables of the service-center serverEPSS 0.8%CVE-2023-37916MEDIUMLeak password hash of any userEPSS 0.8%CVE-2023-5359LOWW3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in PlaintextEPSS 0.8%CVE-2024-41672HIGHDuckDB: sniff_csv provides filesystem access even when enable_external_access is disabledEPSS 0.8%CVE-2021-42522—There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrecEPSS 0.8%CVE-2021-21584HIGHDell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability. AnEPSS 0.8%CVE-2022-0708MEDIUMTeam Creator's Email Address is disclosed to Team Members via one of the APIsEPSS 0.8%CVE-2022-2401MEDIUMTeam members could access sensitive information of other users via an API callEPSS 0.8%CVE-2023-1681MEDIUMXunrui CMS test.php information disclosureEPSS 0.8%CVE-2026-23659HIGHAzure Data Factory Information Disclosure VulnerabilityEPSS 0.8%CVE-2022-2704MEDIUMSourceCodester Simple E-Learning System downloadFiles.php information disclosureEPSS 0.8%CVE-2022-24398—Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to accessEPSS 0.8%