Weaknesses of type CWE-200

4,915 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2021-22825HIGHA CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker to access the systemEPSS 0.8%CVE-2020-15794—A vulnerability has been identified in Desigo Insight (All versions). Some error messages in the web application show the absolute path to tEPSS 0.8%CVE-2025-3975MEDIUMScriptAndTools eCommerce-website-in-PHP subscriber-csv.php information disclosureEPSS 0.8%CVE-2024-27456CRITICALrack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.EPSS 0.8%CVE-2021-22047—In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllersEPSS 0.8%CVE-2024-1404MEDIUMLinksys WRT54GL Web Management Interface SysInfo.htm information disclosureEPSS 0.8%CVE-2023-40735HIGHButterfly Button Project - Sensitive Information DisclosureEPSS 0.8%CVE-2023-0814MEDIUMProfile Builder – User Profile & User Registration Forms <= 3.9.0 - Sensitive Information Disclosure via ShortcodeEPSS 0.8%CVE-2022-35290HIGHUnder certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.EPSS 0.8%CVE-2022-25990MEDIUMOn 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions whicEPSS 0.8%CVE-2023-25165MEDIUMgetHostByName Function Information DisclosureEPSS 0.8%CVE-2025-43189CRITICALThis issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may EPSS 0.8%CVE-2023-5254MEDIUMAI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_userEPSS 0.8%CVE-2025-7874MEDIUMMetasoft 美特软件 MetaCRM env.jsp information disclosureEPSS 0.8%CVE-2026-47751MEDIUMClaude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret ExfiltrationEPSS 0.8%CVE-2026-5585MEDIUMTencent AI-Infra-Guard Task Detail Endpoint task_manager.go information disclosureEPSS 0.8%CVE-2024-31455MEDIUMMinder GetRepositoryByName data leakEPSS 0.8%CVE-2024-24758LOWProxy-Authorization header not cleared on cross-origin redirect in fetch in UndiciEPSS 0.8%CVE-2021-24661—PostX Gutenberg Blocks Saved Templates Addon < 2.4.10 - Private Content DisclosureEPSS 0.8%CVE-2023-23592HIGHWALLIX Access Manager 3.x through 4.0.x allows a remote attacker to access sensitive information.EPSS 0.8%