Weaknesses of type CWE-200

4,939 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-52203HIGHAn issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.EPSS 0.5%CVE-2026-39079HIGHAn issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modEPSS 0.5%CVE-2023-5134MEDIUMEasy Registration Forms <= 2.1.1 - Authenticated (Subscriber+) Information Disclosure via ShortcodeEPSS 0.5%CVE-2026-39007HIGHAn issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export comEPSS 0.5%CVE-2026-52474HIGHAn issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.EPSS 0.5%CVE-2026-73622HIGHGitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()EPSS 0.5%CVE-2023-25500LOWPossible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1EPSS 0.5%CVE-2025-32044HIGHMoodle: unauthenticated rest api user data exposureEPSS 0.5%CVE-2024-42435MEDIUMZoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Sensitive Information ExposureEPSS 0.5%CVE-2025-21620HIGHDeno's authorization headers not dropped when redirecting cross-originEPSS 0.5%CVE-2026-57474MEDIUMDeloitte AI Assist for Customer information disclosureEPSS 0.5%CVE-2024-39822MEDIUMZoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Sensitive Information ExposureEPSS 0.5%CVE-2026-20939MEDIUMWindows File Explorer Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-34905MEDIUMApache Answer: Unlisted Questions Accessible via Direct API AccessEPSS 0.5%CVE-2024-26477HIGHAn issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api parameter of the oauth,EPSS 0.5%CVE-2025-5436MEDIUMMultilaser Sirius RE016 cstecgi.cgi information disclosureEPSS 0.5%CVE-2026-32270LOWCraft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous paymentsEPSS 0.5%CVE-2026-20937MEDIUMWindows File Explorer Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-6429MEDIUMnetrc credential leak with reused proxy connectionEPSS 0.5%CVE-2022-37438LOWInformation disclosure via the dashboard drilldown in Splunk EnterpriseEPSS 0.5%