Weaknesses of type CWE-200

4,919 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-7328MEDIUMYouDianCMS information disclosureEPSS 0.7%CVE-2021-23193HIGHImproper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators EPSS 0.7%CVE-2021-36091LOWUnautorized access to the calendar appointmentsEPSS 0.7%CVE-2021-23204HIGHExposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be eEPSS 0.7%CVE-2024-35230MEDIUMWelcome and About GeoServer pages communicate version and revision informationEPSS 0.7%CVE-2019-3811MEDIUMA vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead oEPSS 0.7%CVE-2026-65017MEDIUMApache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)EPSS 0.7%CVE-2025-15082MEDIUMTOZED ZLT M30s Web Management proc_post information disclosureEPSS 0.7%CVE-2024-23662MEDIUMAn exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 thEPSS 0.7%CVE-2023-48294MEDIUMBroken Access control on Graphs Feature in LibreNMSEPSS 0.7%CVE-2023-6105MEDIUMManageEngine Information Disclosure in Multiple ProductsEPSS 0.7%CVE-2025-53066HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). EPSS 0.7%CVE-2022-47410CRITICALAn issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 tEPSS 0.7%CVE-2022-47411CRITICALAn issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 tEPSS 0.7%CVE-2021-39089MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.7%CVE-2018-3826—In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameEPSS 0.7%CVE-2024-29898MEDIUMOversight in fix for GHSA-4rcf-3cj2-46mq may have exposed suppressed wiki requests on private wikisEPSS 0.7%CVE-2026-26014MEDIUMPion DTLS uses random nonce generation with AES GCM ciphers risks leaking the authentication keyEPSS 0.7%CVE-2025-34220MEDIUMVasion Print (formerly PrinterLogic) Unauthenticated API Leaks Group InformationEPSS 0.7%CVE-2026-20932MEDIUMWindows File Explorer Information Disclosure VulnerabilityEPSS 0.7%