Weaknesses of type CWE-200

4,927 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-41964MEDIUMBigBlueButton contains Response leaks in anonymous pollsEPSS 0.6%CVE-2023-6001MEDIUMPrometheus Metrics Accessible Pre-AuthenticationEPSS 0.6%CVE-2026-2148MEDIUMTenda AC21 Web Management DownloadFlash information disclosureEPSS 0.6%CVE-2026-53571HIGHVite: `server.fs.deny` bypass on Windows alternate pathsEPSS 0.6%CVE-2026-10865MEDIUMCost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret KeysEPSS 0.6%CVE-2026-18059MEDIUMPixelYourSite <= 11.2.1 - Unauthenticated Sensitive Information Exposure via Order-Received Endpoint Missing Key ValidationEPSS 0.6%CVE-2024-35166MEDIUMWordPress FileBird – WordPress Media Library Folders & File Manager plugin <= 5.6.3 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2025-32958CRITICALAdept exposed the GITHUB_TOKEN in workflow run artifactEPSS 0.6%CVE-2024-26480HIGHAn issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin parameter.EPSS 0.6%CVE-2026-69805HIGH.NET Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-20991MEDIUMVulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affecEPSS 0.6%CVE-2024-43803MEDIUMBMO can expose particularly named secrets from other namespaces via BMH CRDEPSS 0.6%CVE-2024-21073HIGHVulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affecteEPSS 0.6%CVE-2024-55272HIGHAn issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function.EPSS 0.6%CVE-2026-75099MEDIUMApache Allura: Unauthenticated REST disclosureEPSS 0.6%CVE-2025-55673MEDIUMApache Superset: Metadata exposure in embedded chartsEPSS 0.6%CVE-2023-3709MEDIUMRoyal Elementor Addons <=1.3.70 - Unauthenticated MailChimp API Key DisclosureEPSS 0.6%CVE-2024-42486MEDIUMCilium vulnerable to information leakage via incorrect ReferenceGrant update logic in Gateway APIEPSS 0.6%CVE-2025-47980MEDIUMWindows Imaging Component Information Disclosure VulnerabilityEPSS 0.6%CVE-2024-39925MEDIUMAn issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organizationEPSS 0.6%