Weaknesses of type CWE-200

4,927 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-42880CRITICALArgoCD ServerSideDiff is vulnerable to Kubernetes Secret ExtractionEPSS 0.6%CVE-2021-44534MEDIUMInsufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosEPSS 0.6%CVE-2025-34051MEDIUMAVTECH DVR Devices Server-Side Request ForgeryEPSS 0.6%CVE-2026-46584LOWApache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parametersEPSS 0.6%CVE-2024-1255MEDIUMsepidz SepidzDigitalMenu Waiters information disclosureEPSS 0.6%CVE-2023-22086HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.6%CVE-2026-84142CRITICALInternally found bugs fixed in Thunderbird 155EPSS 0.6%CVE-2017-9369LOWIn BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, an information disclosure vulnerability in the defaulEPSS 0.6%CVE-2026-19229MEDIUMSourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosureEPSS 0.6%CVE-2024-25118MEDIUMInformation Disclosure of Hashed Passwords in TYPO3 Backend FormsEPSS 0.6%CVE-2025-61594LOWURI Credential Leakage Bypass over CVE-2025-27221EPSS 0.6%CVE-2022-3460HIGHIn affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed EPSS 0.6%CVE-2025-65717MEDIUMAn issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML pEPSS 0.6%CVE-2026-36355HIGHThe rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access controEPSS 0.6%CVE-2026-54203CRITICALTeamDavid: Memory Leak leaking sensitive informationEPSS 0.6%CVE-2021-3800—A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users toEPSS 0.6%CVE-2024-50312MEDIUMGraphql: information disclosure via graphql introspection in openshiftEPSS 0.6%CVE-2026-29066MEDIUMArbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLIEPSS 0.6%CVE-2026-56238HIGHCapgo - Unauthenticated Information Disclosure via PostgREST global_stats EndpointEPSS 0.6%CVE-2022-41329MEDIUMAn exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 andEPSS 0.6%