Weaknesses of type CWE-200

4,898 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-2462MEDIUMTransposh WordPress Translation <= 1.0.9.6 - Sensitive Information DisclosureEPSS 3.7%CVE-2016-6548—Zizai Tech Nut mobile application makes requests using HTTP, which includes the users session tokenEPSS 3.7%CVE-2025-49741HIGHMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 3.6%CVE-2019-5016CRITICALAn exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functioEPSS 3.6%CVE-2018-15919MEDIUMRemotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a targEPSS 3.6%CVE-2020-8169—curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over thEPSS 3.5%CVE-2018-5407—Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel EPSS 3.4%CVE-2018-0425—Cisco RV110W, RV130W, and RV215W Routers Management Interface Information Disclosure VulnerabilityEPSS 3.4%CVE-2026-22240CRITICALPlaintext Passwords Vulnerability in BLUVOYIXEPSS 3.4%CVE-2017-7520—OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-iEPSS 3.4%CVE-2014-2356—Innominate mGuard Exposure of Sensitive Information to an Unauthorized ActorEPSS 3.4%CVE-2025-59434CRITICALCritical Multi-Tenant Variable Disclosure in Flowise Cloud via Custom JavaScript FunctionEPSS 3.4%CVE-2018-0442HIGHCisco Wireless LAN Controller Software Control and Provisioning of Wireless Access Points Protocol Information Disclosure VulnerabilityEPSS 3.3%CVE-2024-50338HIGHCarriage-return character in remote URL allows malicious repository to leak credentials in Git Credential ManagerEPSS 3.2%CVE-1999-0468HIGHInternet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.EPSS 3.2%CVE-2017-6752—A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2) could allow an unauthenticated, remoteEPSS 3.2%CVE-2025-55976HIGHIntelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local netwEPSS 3.2%CVE-2022-27775HIGHAn information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connectEPSS 3.2%CVE-2023-34092HIGHVite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)EPSS 3.1%CVE-2018-10911MEDIUMA flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaEPSS 3.1%