Weaknesses of type CWE-200

4,921 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-9539MEDIUMAn information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to EPSS 0.6%CVE-2024-13567HIGHAwesome Support – WordPress HelpDesk & Support Plugin <= 6.3.1 - Unauthenticated Sensitive Information Exposure Through Unprotected DirectoryEPSS 0.6%CVE-2026-2975MEDIUMFastApiAdmin Custom Documentation Endpoint init_app.py reset_api_docs information disclosureEPSS 0.6%CVE-2026-54183MEDIUMApache Airflow: Airflow Variables were not masked in the UI for authenticated usersEPSS 0.6%CVE-2022-4206MEDIUMA sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the AuthorEPSS 0.6%CVE-2026-75158MEDIUMApache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filterEPSS 0.6%CVE-2026-48891MEDIUMApache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.targetEPSS 0.6%CVE-2025-59469CRITICALThis vulnerability allows a Backup or Tape Operator to write files as root.EPSS 0.6%CVE-2023-37263MEDIUMStrapi's field level permissions not being respected in relationship titleEPSS 0.6%CVE-2024-32100MEDIUMWordPress Easy Digital Downloads plugin <= 3.2.11 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2024-28340HIGHAn information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allowsEPSS 0.6%CVE-2024-7925MEDIUMZZCMS eginfo.php information disclosureEPSS 0.6%CVE-2022-39335MEDIUMSynapse does not apply enough checks to servers requesting auth events of events in a roomEPSS 0.6%CVE-2024-32967MEDIUMZitadel exposes internal database user name and host informationEPSS 0.6%CVE-2026-32890CRITICALAnchorr: Stored XSS in User Mapping dropdown allows unprivileged Discord users to exfiltrate all secrets via /api/configEPSS 0.6%CVE-2026-45788MEDIUMDiscourse: Secure uploads exposed by hotlinked image copyingEPSS 0.6%CVE-2025-59294LOWWindows Taskbar Live Preview Information Disclosure VulnerabilityEPSS 0.6%CVE-2022-31069MEDIUMPotential Authorization Header Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxyEPSS 0.6%CVE-2022-31070MEDIUMPotential Sensitive Cookie Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxyEPSS 0.6%CVE-2023-28732MEDIUMMissing access control affecting the AcyMailing plugin for JoomlaEPSS 0.6%