Weaknesses of type CWE-200

4,920 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-1968HIGHAuthorization Header Leakage in scrapy/scrapy on Scheme Change RedirectsEPSS 0.7%CVE-2022-23726MEDIUMPingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amoEPSS 0.7%CVE-2026-55500CRITICAL9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database TakeoverEPSS 0.7%CVE-2023-23978MEDIUMWordPress WP Client Reports Plugin <= 1.0.16 is vulnerable to Sensitive Data ExposureEPSS 0.7%CVE-2022-24762MEDIUMExposure of Sensitive Information to an Unauthorized Actor in sysend.jsEPSS 0.7%CVE-2023-33174MEDIUMWindows Cryptographic Information Disclosure VulnerabilityEPSS 0.7%CVE-2017-20178LOWCodiad process.php saveJSON information disclosureEPSS 0.7%CVE-2021-40360—A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versionEPSS 0.7%CVE-2023-44253MEDIUMAn exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 aEPSS 0.7%CVE-2023-4139HIGHWP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory ListingEPSS 0.7%CVE-2022-36101MEDIUMSensitive data in backend customer moduleEPSS 0.7%CVE-2024-23962MEDIUMAlpine Halo9 Missing AuthenticationEPSS 0.7%CVE-2024-32781HIGHWordPress Email Customizer for WooCommerce plugin <= 2.6.0 - Sensitive Data Exposure vulnerabilityEPSS 0.7%CVE-2024-1643CRITICALUnauthorized Organization Access in lunary-ai/lunaryEPSS 0.7%CVE-2019-25210CRITICALAn issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flEPSS 0.7%CVE-2024-32726HIGHWordPress Frontend Dashboard plugin <= 2.2.2 - Sensitive Data Exposure on PII vulnerabilityEPSS 0.7%CVE-2024-32816HIGHWordPress Combo Blocks plugin <= 2.2.78 - Sensitive Data Exposure via API vulnerabilityEPSS 0.7%CVE-2022-39212MEDIUMLast video frame is still sent after video is disabled in a call in Nextcloud TalkEPSS 0.7%CVE-2023-6615LOWTypecho manage-users.php information disclosureEPSS 0.7%CVE-2024-2093MEDIUMVK All in One Expansion Unit <= 9.95.0.1 - Information ExposureEPSS 0.7%