Weaknesses of type CWE-200

4,920 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-22421HIGHPotential authentication and CSRF tokens leak in JupyterLabEPSS 0.7%CVE-2021-3590—A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the AEPSS 0.7%CVE-2022-1070HIGHCHANNEL ACCESSIBLE BY NON-ENDPOINT CWE-300EPSS 0.7%CVE-2023-22586HIGHLocal File Inclusion in Danfoss AK-EM100EPSS 0.7%CVE-2023-23620MEDIUMDiscourse restricted tag routes leak topic informationEPSS 0.7%CVE-2022-39013—Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials enables the attacker tEPSS 0.7%CVE-2026-19363MEDIUMlmammino oidc-authorizer Lambda Authorizer handler.rs log fileEPSS 0.7%CVE-2024-6861HIGHForeman: foreman: oauth secret exposure via unauthenticated access to the graphql apiEPSS 0.7%CVE-2021-27422HIGHGE UR family exposure of sensitive information to an unauthorized actorEPSS 0.7%CVE-2026-20827MEDIUMTablet Windows User Interface (TWINUI) Subsystem Information Disclosure VulnerabilityEPSS 0.7%CVE-2023-37972MEDIUMWordPress WooCommerce Product Stock Alert Plugin <= 2.0.1 is vulnerable to Sensitive Data ExposureEPSS 0.7%CVE-2023-40662MEDIUMWordPress Cookies and Content Security Policy Plugin <= 2.15 is vulnerable to Sensitive Data ExposureEPSS 0.7%CVE-2023-23763MEDIUMInformation disclosure in GitHub Enterprise Server leading to private repository leakageEPSS 0.7%CVE-2025-25192MEDIUMGLPI allows unauthorized access to debug modeEPSS 0.7%CVE-2026-20823MEDIUMWindows File Explorer Information Disclosure VulnerabilityEPSS 0.7%CVE-2023-41735MEDIUMWordPress Email posts to subscribers Plugin <= 6.2 is vulnerable to Sensitive Data ExposureEPSS 0.7%CVE-2026-81531MEDIUMUnauthenticated Account Information Disclosure in Multiple Omada ControllersEPSS 0.7%CVE-2020-1902—A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for AndEPSS 0.7%CVE-2026-41186MEDIUMUnauthenticated Go pprof exposure in Calico debug serverEPSS 0.7%CVE-2024-53862MEDIUMArgo Workflows Allows Access to Archived Workflows with Fake Token in `client` modeEPSS 0.7%