Weaknesses of type CWE-200

4,927 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-24003MEDIUMExposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby EPSS 0.6%CVE-2026-2147MEDIUMTenda AC21 Web Management DownloadLog information disclosureEPSS 0.6%CVE-2025-61780MEDIUMRack has Possible Information Disclosure VulnerabilityEPSS 0.6%CVE-2026-42164CRITICALMahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows EPSS 0.6%CVE-2026-25219MEDIUMApache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view accessEPSS 0.6%CVE-2022-32836—This issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to accessEPSS 0.6%CVE-2024-6560MEDIUMAddonify – Quick View For WooCommerce <= 1.2.16 - Unauthenticated Full Path DislcosureEPSS 0.6%CVE-2023-46820MEDIUMWordPress Image Regenerate & Select Crop Plugin <= 7.3.0 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2025-57441CRITICALThe Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on portEPSS 0.6%CVE-2022-38456MEDIUMWordPress Ajax Search Lite Plugin <= 4.10.3 is vulnerable to Sensitive Data ExposureEPSS 0.6%CVE-2022-32784—The issue was addressed with improved UI handling. This issue is fixed in Safari 15.6, iOS 15.6 and iPadOS 15.6. Visiting a maliciously crafEPSS 0.6%CVE-2024-41108HIGHFOG Sensitive Information DisclosureEPSS 0.6%CVE-2023-28334MEDIUMMoodle: users' name enumeration possible via idor on learning plans pageEPSS 0.6%CVE-2024-37115HIGHWordPress Newspack Blocks plugin <= 3.0.8 - Sensitive Data Exposure vulnerabilityEPSS 0.6%CVE-2024-48310HIGHAutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers may use these keys tEPSS 0.6%CVE-2026-15012MEDIUMDemi <= 0.0.8 - Unauthenticated Information Exposure to Arbitrary Directory CopyEPSS 0.6%CVE-2022-41914LOWNon-constant-time SCIM token comparison in Zulip ServerEPSS 0.6%CVE-2024-33436MEDIUMAn issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS variablesEPSS 0.6%CVE-2024-37110HIGHWordPress WishList Member X plugin < 3.26.7 - Unauthenticated Settings & Users Data Dump vulnerabilityEPSS 0.6%CVE-2023-25544HIGH Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote acceEPSS 0.5%