Weaknesses of type CWE-200

4,921 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-44991MEDIUMWordPress Media File Renamer Plugin <= 5.6.9 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2023-33955MEDIUMMinio console object names with RIGHT-TO-LEFT OVERRIDE unicode character can be exploitedEPSS 0.6%CVE-2026-55178HIGHGeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile dataEPSS 0.6%CVE-2025-26521HIGHApache CloudStack: CKS cluster in project exposes user API keysEPSS 0.6%CVE-2024-3574HIGHAuthorization Header Leak During Cross-Domain Redirect in scrapy/scrapyEPSS 0.6%CVE-2025-43356MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, EPSS 0.6%CVE-2026-20862MEDIUMWindows Management Services Information Disclosure VulnerabilityEPSS 0.6%CVE-2026-75162MEDIUMAn information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware VEPSS 0.6%CVE-2022-43927MEDIUMIBM Db2 for Linux, UNIX and Windows information disclosureEPSS 0.6%CVE-2024-28120MEDIUMAPI key leak in codeium-chromeEPSS 0.6%CVE-2026-42498HIGHApache Tomcat: WebSocket authentication header exposureEPSS 0.6%CVE-2021-32050MEDIUMSome MongoDB Drivers may publish events containing authentication-related data to a command listener configured by an applicationEPSS 0.6%CVE-2024-51123HIGHAn issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote attacker to obtain sensitive information viaEPSS 0.6%CVE-2022-35247MEDIUMA information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in the getRoomRoles MeteoEPSS 0.6%CVE-2025-7565MEDIUMLB-LINK BL-AC3600 Web Management Interface lighttpd.cgi geteasycfg information disclosureEPSS 0.6%CVE-2024-26119MEDIUMAdobe Experience Manager | Information Exposure (CWE-200)EPSS 0.6%CVE-2024-25917HIGHWordPress WP Setup Wizard plugin <= 1.0.8.1 - Auth. Full Database Download VulnerabilityEPSS 0.6%CVE-2025-12491HIGHSenstar Symphony FetchStoredLicense Information Disclosure VulnerabilityEPSS 0.6%CVE-2026-48050HIGHArc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoSEPSS 0.6%CVE-2024-33669MEDIUMAn issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is beinEPSS 0.6%