Weaknesses of type CWE-200

4,922 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-47597MEDIUMWordPress Popup Maker Plugin <= 1.17.1 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2023-51154CRITICALJizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.EPSS 0.6%CVE-2025-59186MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-59211MEDIUMWindows Push Notification Information Disclosure VulnerabilityEPSS 0.6%CVE-2026-32633CRITICALGlances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`EPSS 0.6%CVE-2025-55336MEDIUMWindows Cloud Files Mini Filter Driver Information Disclosure VulnerabilityEPSS 0.6%CVE-2024-1769MEDIUMJM Twitter Cards <= 14 - Information Exposure via Meta DescriptionEPSS 0.6%CVE-2023-34098MEDIUMDependency configuration exposed in ShopwareEPSS 0.6%CVE-2024-11297MEDIUMPage Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.6 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.6%CVE-2026-42213MEDIUMSolidCAM-GPPL-IDE: Path traversal in `inc` directive enables file probing and NTLM-hash leakEPSS 0.6%CVE-2024-39683MEDIUMZITADEL Vulnerable to Session Information LeakageEPSS 0.6%CVE-2022-39359MEDIUMMetabase's GeoJSON validation doesn't prevent redirects to blocked URLsEPSS 0.6%CVE-2024-21077HIGHVulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts LOV). Supported versions that are aEPSS 0.6%CVE-2025-58752LOWVite's `server.fs` settings were not applied to HTML filesEPSS 0.6%CVE-2024-0909MEDIUMAnonymous Restricted Content <= 1.6.2 - Protection Mechanism BypassEPSS 0.6%CVE-2024-26864HIGHtcp: Fix refcnt handling in __inet_hash_connect().EPSS 0.6%CVE-2017-12279—A vulnerability in the packet processing code of Cisco IOS Software for Cisco Aironet Access Points could allow an unauthenticated, adjacentEPSS 0.6%CVE-2026-45623HIGHPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsEPSS 0.6%CVE-2023-22476MEDIUMMantisBT: Exposure of Private issues' summary to unauthorized usersEPSS 0.6%CVE-2022-30732MEDIUMExposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive informatioEPSS 0.6%