Weaknesses of type CWE-200

4,927 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-25544HIGH Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote acceEPSS 0.5%CVE-2024-27120HIGHLocal File Inclusion in ComfortKey before version 24.1.2EPSS 0.5%CVE-2023-24567HIGH Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access toEPSS 0.5%CVE-2026-52101CRITICALAn issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadREPSS 0.5%CVE-2026-86284MEDIUMjaychouchannel Tourism-Management-System CommonController.java getOption information disclosureEPSS 0.5%CVE-2026-88874HIGHAVideo through c3edcc274c389816d434acadac07ee78eaf330c1 Authentication BypassEPSS 0.5%CVE-2025-24360MEDIUMOpening a malicious website while running a Nuxt dev server could allow read-only access to codeEPSS 0.5%CVE-2026-42047HIGHInngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methodsEPSS 0.5%CVE-2026-94413HIGHjshERP through 3.6 Password Hash Disclosure via /user/infoEPSS 0.5%CVE-2026-60264CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.EPSS 0.5%CVE-2020-36835MEDIUMMigration, Backup, Staging – WPvivid <= 0.9.35 - Sensitive Information DisclosureEPSS 0.5%CVE-2026-82306MEDIUMStarRocks Query Detail Endpoint Returns Every User's Query HistoryEPSS 0.5%CVE-2026-14161HIGHAdvantech|Hospital Queuing Management - Sensitive Data ExposureEPSS 0.5%CVE-2024-12426MEDIUMURL fetching can be used to exfiltrate arbitrary INI file values and environment variablesEPSS 0.5%CVE-2024-30263HIGHThe PDF Viewer macro can be used to view PDF attachments with restricted accessEPSS 0.5%CVE-2026-47340MEDIUMApache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.EPSS 0.5%CVE-2026-4660HIGHGo-getter may allow to arbitrary filesystem reads through git operationsEPSS 0.5%CVE-2025-55683MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-25120MEDIUMImproper Access Control of Resources Referenced by t3:// URI Scheme in TYPO3EPSS 0.5%CVE-2024-4266MEDIUMMetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticated Sensitive Information ExposureEPSS 0.5%