Weaknesses of type CWE-200

4,917 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-22577CRITICALWhite Rabbit Switch - Password Disclosure VulnerabilityEPSS 0.8%CVE-2024-36471HIGHApache Allura: sensitive information exposure via DNS rebindingEPSS 0.8%CVE-2021-21596CRITICALDell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remEPSS 0.8%CVE-2024-33309HIGHAn issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to obtain sensitive information viEPSS 0.8%CVE-2023-5576HIGHMigration, Backup, Staging – WPvivid <= 0.9.91 - Google Drive Client Secret ExposureEPSS 0.7%CVE-2025-27675CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Vulnerable OpenID Implementation V-EPSS 0.7%CVE-2013-10030MEDIUMExit Box Lite Plugin wordpress-exit-box-lite.php information disclosureEPSS 0.7%CVE-2023-27478MEDIUMDisclosure of unrelated data in libmemcached-awesome EPSS 0.7%CVE-2022-39307MEDIUMGrafana subject to Exposure of Sensitive Information resulting in User enumeration via forget passwordEPSS 0.7%CVE-2024-23302HIGHCouchbase Server before 7.2.4 has a private key leak in goxdcr.log.EPSS 0.7%CVE-2023-40049MEDIUMWS_FTP Server Information Disclosure via Directory ListingEPSS 0.7%CVE-2020-12518MEDIUMPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.EPSS 0.7%CVE-2023-49981HIGHA directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the EPSS 0.7%CVE-2023-20055HIGHCisco DNA Center Privilege Escalation VulnerabilityEPSS 0.7%CVE-2023-32082LOWetcd key name can be accessed via LeaseTimeToLive APIEPSS 0.7%CVE-2026-2861MEDIUMFoswiki Changes/Viewfile/Oops information disclosureEPSS 0.7%CVE-2025-45620HIGHAn issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted requestEPSS 0.7%CVE-2022-31177LOWPossible to infer sensitive information through query strings in Flask-AppBuilderEPSS 0.7%CVE-2021-20250—A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on theEPSS 0.7%CVE-2022-45103MEDIUM Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerabiEPSS 0.7%