Weaknesses of type CWE-200

4,932 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-48799HIGHAn issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware upEPSS 0.5%CVE-2024-48798HIGHAn issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmwaEPSS 0.5%CVE-2024-48796HIGHAn issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update process.EPSS 0.5%CVE-2024-3706MEDIUMExposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenGnsysEPSS 0.5%CVE-2022-39378MEDIUMDisplaying user badges can leak topic titles to users that have no access to the topicEPSS 0.5%CVE-2022-43868MEDIUMIBM Security Verify Access information disclosureEPSS 0.5%CVE-2021-26333—AMD Chipset Driver Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-34785HIGHRack: Local file inclusion in `Rack::Static` via URL Prefix MatchingEPSS 0.5%CVE-2026-11431HIGHPath Traversal in Altium Projects Service Allows Arbitrary File ReadEPSS 0.5%CVE-2026-32865CRITICALOPEXUS eComplaint and eCase insecure password resetEPSS 0.5%CVE-2024-4159MEDIUMProtection mechanismsEPSS 0.5%CVE-2024-51163HIGHA Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker to obtain sensitive EPSS 0.5%CVE-2025-0403MEDIUM1902756969 reggie Phone Number Validation sendMsg information disclosureEPSS 0.5%CVE-2022-40696LOWWordPress Advanced Custom Fields Plugin 3.1.1-6.0.2 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2024-12255MEDIUMAccept Stripe Payments Using Contact Form 7 <= 2.5 - Unauthenticated Information ExposureEPSS 0.5%CVE-2025-27615HIGHumatiGateway's UI publicly accessible in provided docker-compose fileEPSS 0.5%CVE-2025-30353HIGHDirectus's webhook trigger flows can leak sensitive dataEPSS 0.5%CVE-2023-50705MEDIUMExposure of Sensitive Information to an Unauthorized Actor in EFACEC UC 500EEPSS 0.5%CVE-2023-2025MEDIUMExposure of Sensitive Information in OpenBlue Enterprise Manager Data CollectorEPSS 0.5%CVE-2026-52203HIGHAn issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.EPSS 0.5%