Weaknesses of type CWE-200

4,927 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-27863MEDIUMIBM Spectrum Protect Plus Server information disclosureEPSS 0.6%CVE-2025-11647LOWTomofun Furbo 360/Furbo Mini GATT Service information disclosureEPSS 0.6%CVE-2023-46315—The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable DiEPSS 0.6%CVE-2024-4021MEDIUMKeenetic KN-1010/KN-1410/KN-1711/KN-1810/KN-1910 Configuration Setting ndmComponents.js information disclosureEPSS 0.6%CVE-2026-41323HIGHKyverno: ServiceAccount token leaked to external servers via apiCall service URLEPSS 0.6%CVE-2025-31492HIGHmod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected dataEPSS 0.6%CVE-2024-27947MEDIUMA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems could allow log messages to be forwardEPSS 0.6%CVE-2024-24548HIGHPayment EX Ver1.1.5b and earlier allows a remote unauthenticated attacker to obtain the information of the user who purchases merchandise usEPSS 0.6%CVE-2023-0614HIGHThe fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacEPSS 0.6%CVE-2026-7167MEDIUMMultiple vulnerabilities in the Assassin game by GaudireEPSS 0.6%CVE-2024-56136MEDIUM/api/v1/jwt/fetch_api_key endpoint can leak if an email address has an account in Zulip serverEPSS 0.6%CVE-2022-31095MEDIUMExposure of Sensitive Information in discourse-chatEPSS 0.6%CVE-2026-84134CRITICALOther issue in the Profile Backup componentEPSS 0.6%CVE-2024-27296MEDIUMDirectus version number disclosureEPSS 0.6%CVE-2023-26026MEDIUMIBM Planning Analytics Cartridge for Cloud Pak for Data information disclosureEPSS 0.6%CVE-2023-24959MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.6%CVE-2024-29036MEDIUMSaleor Storefront session leak in cacheEPSS 0.6%CVE-2026-13697HIGHundici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directivesEPSS 0.6%CVE-2023-22611HIGHA CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specEPSS 0.6%CVE-2026-92708HIGHdevalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node BuffersEPSS 0.6%