Weaknesses of type CWE-200

4,927 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-4266MEDIUMMetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticated Sensitive Information ExposureEPSS 0.5%CVE-2025-30702MEDIUMVulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. Supported versions that are affected are 19.EPSS 0.5%CVE-2023-28421MEDIUMWordPress WordPress Email Marketing Plugin – WP Email Capture Plugin <= 3.10 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2023-2514MEDIUMDB username/password revealed in application logsEPSS 0.5%CVE-2025-2277HIGHExposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leEPSS 0.5%CVE-2026-55389HIGHdatamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`EPSS 0.5%CVE-2025-27785HIGHApplio allows arbitrary file read in train.py export_index functionEPSS 0.5%CVE-2024-32716MEDIUMWordPress StreamWeasels Twitch Integration plugin <= 1.7.8 - API Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2026-86464CRITICALIn the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deploEPSS 0.5%CVE-2024-37895MEDIUMAPI Key Leak in lobe-chatEPSS 0.5%CVE-2021-33146MEDIUMImproper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unautEPSS 0.5%CVE-2023-1775MEDIUMUnsanitized events sent over Websocket to regular users in a High Availability environmentEPSS 0.5%CVE-2026-59828MEDIUMDiscourse: Hidden post revisions leak through adjacent visible diffsEPSS 0.5%CVE-2024-23193MEDIUME-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of theEPSS 0.5%CVE-2022-39385MEDIUMUsers erroneously and transparently added to private messages in DiscourseEPSS 0.5%CVE-2026-55729HIGHLoytec LWEB802: Exposure of Sensitive Information in browser localStorageEPSS 0.5%CVE-2024-5067MEDIUMExposure of Sensitive Information to an Unauthorized Actor in GitLabEPSS 0.5%CVE-2026-7166CRITICALMultiple vulnerabilities in the Assassin game by GaudireEPSS 0.5%CVE-2023-41786MEDIUMDatabase backups availability by low-privileged usersEPSS 0.5%CVE-2024-2632HIGHInformation Exposure Vulnerability on Meta4 HREPSS 0.5%