Weaknesses of type CWE-200

4,927 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-50312MEDIUMGraphql: information disclosure via graphql introspection in openshiftEPSS 0.6%CVE-2024-0472LOWcode-projects Dormitory Management System modifyuser.php information disclosureEPSS 0.6%CVE-2024-8538MEDIUMBig File Uploads <= 2.1.2 - Authenticated (Author+) Full Path DisclosureEPSS 0.6%CVE-2022-47160MEDIUMWordPress Wp Social Plugin <= 1.9.0 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2025-27784HIGHApplio allows arbitrary file read in train.py export_pth functionEPSS 0.6%CVE-2021-24945—Like Button Rating < 2.6.38 - Unauthorised Vote Export to Email & IP Addresses DisclosureEPSS 0.6%CVE-2022-36077HIGHElectron subject to Exfiltration of hashed SMB credentials on Windows via file:// redirectEPSS 0.6%CVE-2020-3525MEDIUMCisco Identity Services Engine Password Disclosure to an Unauthorized Actor VulnerabilityEPSS 0.6%CVE-2025-14915MEDIUMIBM WebSphere Application Server Liberty is affected by a privilege escalation vulnerabilityEPSS 0.6%CVE-2026-32938CRITICALSiYuan has an Arbitrary File Read in its Desktop Publish ServiceEPSS 0.6%CVE-2021-3688—A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a reEPSS 0.6%CVE-2026-74986CRITICALSite isolation issue in the CSS Parsing and Computation componentEPSS 0.6%CVE-2024-26479MEDIUMAn issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command execution function.EPSS 0.6%CVE-2024-40836HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS SonomEPSS 0.6%CVE-2022-39167MEDIUMIBM Spectrum Virtualize information disclosureEPSS 0.6%CVE-2023-34466MEDIUMXWiki Platform's tags on non-viewable pages can be revealed to usersEPSS 0.6%CVE-2024-32780MEDIUMWordPress VikRentCar Car Rental Management System plugin <= 1.3.2 - Sensitive Data Exposure via Invoices vulnerabilityEPSS 0.6%CVE-2026-28276HIGHInitiative Allows Unauthenticated Access to Uploaded Documents via Public /uploads/ EndpointEPSS 0.6%CVE-2023-47244MEDIUMWordPress Email Marketing for WooCommerce by Omnisend Plugin <= 1.13.8 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2024-12434MEDIUMSureMembers <= 1.10.6 - Sensitive Information ExposureEPSS 0.6%