Weaknesses of type CWE-200

4,926 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-35171MEDIUMWordPress Academy LMS plugin <= 1.9.25 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2024-7414MEDIUMPDF Builder for WPForms <= 1.2.116 - Unauthenticated Full Path DisclosureEPSS 0.6%CVE-2024-6562MEDIUMaffiliate-toolkit <= 3.5.5 - Unauthenticated Full Path DislcosureEPSS 0.6%CVE-2024-34388HIGHWordPress GDPR Compliance plugin <= 1.2.5 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2023-39739HIGHThe leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted brEPSS 0.6%CVE-2026-44881HIGHPortainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-UpdateEPSS 0.6%CVE-2023-39736HIGHThe leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted brEPSS 0.6%CVE-2023-39737HIGHThe leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messaEPSS 0.6%CVE-2023-39735HIGHThe leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadEPSS 0.6%CVE-2022-36777MEDIUMIBM Cloud Pak for Security information disclosureEPSS 0.6%CVE-2024-0242HIGHUnauthorized access to settings in Qolsys IQ Panel 4 and IQ4 HubEPSS 0.6%CVE-2024-44152HIGHA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be aEPSS 0.6%CVE-2023-1858MEDIUMSourceCodester Earnings and Expense Tracker App index.php information disclosureEPSS 0.6%CVE-2024-8326HIGHs2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241114 - Authenticated (Contributor+) Sensitive Information ExposureEPSS 0.6%CVE-2024-8884CRITICALCWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacEPSS 0.6%CVE-2025-63094HIGHXiangShan Nanhu V2 and XiangShan Kunmighu V3 were discovered to use speculative execution and indirect branch prediction, allowing attackersEPSS 0.6%CVE-2026-55870LOWGoCD is vulnerable to credential exposure when admins insecurely configure material URLsEPSS 0.6%CVE-2023-22580MEDIUMSequalize - Bad query filtering leading to SQL errorsEPSS 0.6%CVE-2022-2408MEDIUMGuest accounts can list all public channelsEPSS 0.6%CVE-2025-23387MEDIUMRancher's SAML-based login via CLI can be denied by unauthenticated usersEPSS 0.6%