Weaknesses of type CWE-200

4,927 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-22611HIGHA CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specEPSS 0.6%CVE-2026-92708HIGHdevalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node BuffersEPSS 0.6%CVE-2025-5334HIGHExposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows EPSS 0.6%CVE-2020-29010MEDIUMAn exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay EPSS 0.6%CVE-2026-49984HIGHKestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\..\` bypasses the `..` guard)EPSS 0.6%CVE-2024-11089MEDIUMAnonymous Restricted Content <= 1.6.5 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureEPSS 0.6%CVE-2022-41917MEDIUMIncorrect Error Handling Allowed Partial File Reads Over REST API in OpenSearchEPSS 0.6%CVE-2025-11443MEDIUMJhumanJ OpnForm Forgotten Password email information exposureEPSS 0.6%CVE-2023-38729MEDIUMIBM Db2 information disclosureEPSS 0.6%CVE-2022-46257—Information disclosure in GitHub Enterprise Server leading to unauthorized viewing of private repository namesEPSS 0.6%CVE-2026-40245HIGHFree5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authenticationEPSS 0.6%CVE-2026-79323HIGHInformation disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 EPSS 0.6%CVE-2026-8198MEDIUMActivity Logs, User Activity Tracking, Multisite Activity Log from Logtivity <= 3.3.6 - Unauthenticated Information Disclosure via REST APIEPSS 0.6%CVE-2024-21205MEDIUMVulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The supported version thaEPSS 0.6%CVE-2026-42880CRITICALArgoCD ServerSideDiff is vulnerable to Kubernetes Secret ExtractionEPSS 0.6%CVE-2026-40166HIGHauthentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth2/access_tokens/EPSS 0.6%CVE-2024-2541MEDIUMPopup Builder <= 4.3.6 - Sensitive Information Exposure via Imported Subscribers CSV FileEPSS 0.6%CVE-2022-36075LOWFile list exposure in Nextcloud Files Access ControlEPSS 0.6%CVE-2026-52837MEDIUMEasy!Appointments has unauthenticated customer PII disclosure on booking reschedule pageEPSS 0.6%CVE-2026-55485HIGHPiccolo Admin: Privilege escalation - admin to superuser via session-token disclosure in GET /api/tables/sessions/.EPSS 0.6%