Weaknesses of type CWE-200

4,920 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-48892MEDIUMApache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic optionsEPSS 0.7%CVE-2026-48828MEDIUMApache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the keyEPSS 0.7%CVE-2026-45192MEDIUMApache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API ResponseEPSS 0.7%CVE-2026-49487MEDIUMApache Airflow: Task-instance API exposes secrets in deferred trigger kwargsEPSS 0.7%CVE-2021-22143LOWElastic APM .NET Agent information disclosureEPSS 0.7%CVE-2026-55447CRITICALLangflow: BaseFileComponent-based nodes arbitrary file read with RCE exploitEPSS 0.7%CVE-2026-69197HIGHUmbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansionEPSS 0.7%CVE-2022-1663—Stop Spam Comments <= 0.2.1.2 - Access Token BypassEPSS 0.7%CVE-2023-47126LOWInformation Disclosure in Install Tool in typo3/cms-installEPSS 0.7%CVE-2026-55553HIGHurllib: Cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakageEPSS 0.7%CVE-2023-20866MEDIUMIn Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive informatioEPSS 0.7%CVE-2022-45634MEDIUMAn issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows authenticated attacker to gain access to sensitive aEPSS 0.7%CVE-2019-15577—An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclEPSS 0.7%CVE-2024-33865HIGHAn issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GEPSS 0.7%CVE-2026-63646MEDIUMCordysCRM MCP Form Configuration Endpoint Exposed to Anonymous UsersEPSS 0.7%CVE-2023-44150HIGHWordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data ExposureEPSS 0.7%CVE-2026-42333MEDIUMquarkus-openapi-generator has overly broad path-parameter matching that sends authentication headers to unintended operationsEPSS 0.7%CVE-2021-22272MEDIUMControlTouch Cloud Service vulnerability: Serial Number can be misused during commissioning phase.EPSS 0.7%CVE-2022-35169—SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decryptEPSS 0.7%CVE-2023-3132MEDIUMMainWP Child <= 4.4.1.1 - Information Disclosure via Back-Up FilesEPSS 0.7%