Weaknesses of type CWE-200

4,927 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-45066MEDIUMWordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2022-36399MEDIUMWordPress Booked Plugin < 2.4.4 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2026-49211MEDIUMSymfony UX: Information exposure via unescaped LIKE wildcards in EntitySearchUtilEPSS 0.5%CVE-2024-53859MEDIUMgo-gh `auth.TokenForHost` violates GitHub host security boundary within a codespaceEPSS 0.5%CVE-2026-25650MEDIUMMCP Salesforce Connector has arbitrary attribute access which leads to disclosure of Salesforce auth tokenEPSS 0.5%CVE-2026-76672CRITICALAuthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN OrchestratorEPSS 0.5%CVE-2024-23344MEDIUMTuleap's content of artifacts might be readable by unauthorized usersEPSS 0.5%CVE-2026-85717MEDIUMAsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect targetEPSS 0.5%CVE-2025-24239MEDIUMA downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to EPSS 0.5%CVE-2024-45792MEDIUMMantisBT vulnerable to information disclosure with user profilesEPSS 0.5%CVE-2018-16862MEDIUMA security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removaEPSS 0.5%CVE-2023-36539MEDIUMExposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.EPSS 0.5%CVE-2026-55390HIGHArbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gateEPSS 0.5%CVE-2025-24279MEDIUMThis issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. EPSS 0.5%CVE-2026-85588MEDIUMphpMyFAQ before 4.1.8 TOTP Secret Exposure via Data ExportEPSS 0.5%CVE-2023-52234MEDIUMWordPress Booster Elite for WooCommerce plugin < 7.1.2 - Auth. Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2023-46128MEDIUMExposure of hashed user passwords via REST API in NautobotEPSS 0.5%CVE-2023-23458MEDIUMSunell DVR – Exposure of Sensitive InformationEPSS 0.5%CVE-2023-52231MEDIUMWordPress Booster Plus for WooCommerce plugin < 7.1.2 - Auth. Sensitive Data Exposure vulnerabilityEPSS 0.5%CVE-2024-23523MEDIUMWordPress Elementor Pro plugin <= 3.19.2 - Contributor+ Arbitrary User Meta Data Retrieval vulnerabilityEPSS 0.5%