Weaknesses of type CWE-200

4,925 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-54151HIGHDirectus allows unauthenticated access to WebSocket events and operationsEPSS 0.6%CVE-2026-40173CRITICALDgraph: Unauthenticated pprof endpoint leaks admin auth tokenEPSS 0.6%CVE-2026-73246HIGHKestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentialsEPSS 0.6%CVE-2022-1911MEDIUMInformation disclosure in M-Files ServerEPSS 0.6%CVE-2024-52517MEDIUMNextcloud Server's global credentials of external storages are sent back to the frontendEPSS 0.6%CVE-2023-45024HIGHBest Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.EPSS 0.6%CVE-2022-23488MEDIUMBigBlueButton vulnerable to Insertion of Sensitive Information Into Sent DataEPSS 0.6%CVE-2024-8072MEDIUMMage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary usersEPSS 0.6%CVE-2023-25680MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.6%CVE-2025-11028MEDIUMgivanz Vvveb Image information disclosureEPSS 0.6%CVE-2021-39008LOWIBM QRadar WinCollect Agent information disclosureEPSS 0.6%CVE-2024-1979LOWQuarkus: information leak in annotationEPSS 0.6%CVE-2026-61397HIGHApache CloudStack: OAuth2 Token Cross-Request LeakEPSS 0.6%CVE-2026-59655HIGHApache CloudStack: Unauthenticated OAuth provider client-secret disclosureEPSS 0.6%CVE-2026-59780HIGHApache CloudStack: LDAP provider configuration disclosureEPSS 0.6%CVE-2026-54603HIGHOAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker hostEPSS 0.6%CVE-2023-44394MEDIUMDisclosure of project names to unauthorized users in MantisBTEPSS 0.6%CVE-2025-9005MEDIUMmtons mblog register information exposureEPSS 0.6%CVE-2024-12984MEDIUMAmcrest IP2M-841B Web Interface webCapsConfig information disclosureEPSS 0.6%CVE-2023-48333MEDIUMWordPress Booster for WooCommerce Plugin <= 7.1.1 is vulnerable to Sensitive Data ExposureEPSS 0.6%