Weaknesses of type CWE-200

4,927 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-45803MEDIUMRequest body not stripped after redirect in urllib3EPSS 0.5%CVE-2023-47222CRITICALMedia Streaming add-onEPSS 0.5%CVE-2024-5067MEDIUMExposure of Sensitive Information to an Unauthorized Actor in GitLabEPSS 0.5%CVE-2025-63958CRITICALMILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authEPSS 0.5%CVE-2026-47136MEDIUMRustFS: Unauthenticated RustFS console license endpoint exposes license metadataEPSS 0.5%CVE-2024-8777HIGHThe SYSCOM Group OMFLOW - Information LeakageEPSS 0.5%CVE-2024-5133CRITICALAccount Takeover via Exposed Recovery Token in lunary-ai/lunaryEPSS 0.5%CVE-2026-53647MEDIUMFOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpointEPSS 0.5%CVE-2023-25965MEDIUMWordPress Upload Resume plugin <= 1.2.0 - Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-37113CRITICALWordPress WishList Member X plugin < 3.26.7 - Unauthenticated Database Backup Download vulnerabilityEPSS 0.5%CVE-2025-12616MEDIUMPHPGurukul News Portal settings.py insertion of sensitive information into debugging codeEPSS 0.5%CVE-2026-9612MEDIUMWhatsOrder <= 1.0.1 - Unauthenticated Sensitive Information Exposure via Predictable Invoice File URLsEPSS 0.5%CVE-2021-3031MEDIUMPAN-OS: Information exposure in Ethernet data frame construction (Etherleak)EPSS 0.5%CVE-2026-37453HIGHInsecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via EPSS 0.5%CVE-2023-27877MEDIUMIBM Planning Analytics Cartridge for Cloud Pak for Data information disclosureEPSS 0.5%CVE-2023-22876MEDIUMIBM Sterling B2B Integrator information disclosureEPSS 0.5%CVE-2024-57716HIGHAn issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselectable function.EPSS 0.5%CVE-2023-35898MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.5%CVE-2026-54659MEDIUMPagy I18n locale option is not validated before being used in a file pathEPSS 0.5%CVE-2026-50222HIGHApache CloudStack: Improper access control in Userdata reference APIsEPSS 0.5%