Weaknesses of type CWE-200

4,917 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-30300CRITICALTenable Vulnerability Disclosure | Sensitive Information Disclosure Via Fake FMPS WorkerEPSS 0.7%CVE-2023-51142HIGHAn issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information.EPSS 0.7%CVE-2023-0838MEDIUMAn issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A EPSS 0.7%CVE-2023-20061MEDIUMCisco Unified Intelligence Center VulnerabilitiesEPSS 0.7%CVE-2026-8385MEDIUMWP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX FallbackEPSS 0.7%CVE-2017-14009—An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated user uses the ChangEPSS 0.7%CVE-2026-4106MEDIUMHT Mega < 3.0.7 – Unauthenticated PII DisclosureEPSS 0.7%CVE-2026-2894MEDIUMfunadmin forget.html getMember information disclosureEPSS 0.7%CVE-2023-24882MEDIUMMicrosoft OneDrive for Android Information Disclosure VulnerabilityEPSS 0.7%CVE-2024-22734MEDIUMAn issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attackers to obtain sensitEPSS 0.7%CVE-2023-46125MEDIUMFides Information Disclosure Vulnerability in Config API EndpointEPSS 0.7%CVE-2022-21642MEDIUMExposure of whisper participants in discourseEPSS 0.7%CVE-2020-7269MEDIUMSensitive Information Exposure in McAfee ATDEPSS 0.7%CVE-2023-38846—An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.EPSS 0.7%CVE-2023-38847—An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.EPSS 0.7%CVE-2023-38845—An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.EPSS 0.7%CVE-2023-38849HIGHAn issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.EPSS 0.7%CVE-2026-40498HIGHFreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cronEPSS 0.7%CVE-2022-39230MEDIUMSecurity issue in fhir-works-on-aws-authz-smartEPSS 0.7%CVE-2025-13920MEDIUMWP Directory Kit <= 1.4.9 - Unauthenticated Email Exposure via wdk_public_actionEPSS 0.7%