Weaknesses of type CWE-200

4,951 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-60167HIGHVulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions thatEPSS 0.4%CVE-2026-50017MEDIUMpnpm binds unscoped user-level npm auth credentials to a repository-selected registryEPSS 0.4%CVE-2024-22435HIGHHPE NonStop Web ViewPoint Enterprise software, Unauthorized accessEPSS 0.4%CVE-2026-87221HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-73883HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.4%CVE-2026-60293HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS - Web Services). Supported versions that arEPSS 0.4%CVE-2026-61116HIGHVulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are afEPSS 0.4%CVE-2026-57231HIGHPodman: Malformed Image can trick podman run into leaking host environment variables into the containerEPSS 0.4%CVE-2026-61159HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience MaEPSS 0.4%CVE-2026-60556HIGHVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are aEPSS 0.4%CVE-2026-34297HIGHVulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versioEPSS 0.4%CVE-2025-21626MEDIUMGLPI vulnerable to exposure of sensitive information in the `status.php` endpointEPSS 0.4%CVE-2026-60315HIGHVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affecteEPSS 0.4%CVE-2024-8780MEDIUMThe SYSCOM Group OMFLOW - Improper Authorization for Data Query FunctionEPSS 0.4%CVE-2026-56337MEDIUMCapgo - Information Disclosure via Unauthenticated RPC Function exist_app_v2EPSS 0.4%CVE-2023-29137MEDIUMAn issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for GrowthExperiments inadverEPSS 0.4%CVE-2023-32710MEDIUMInformation Disclosure via the ‘copyresults’ SPL CommandEPSS 0.4%CVE-2023-52126MEDIUMWordPress Send Users Email Plugin <= 1.4.3 is vulnerable to Sensitive Data ExposureEPSS 0.4%CVE-2026-43885HIGHWWBN AVideo: Exposure of Sensitive Information to an Unauthorized Actor and Missing AuthorizationEPSS 0.4%CVE-2026-84179MEDIUMApache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology PageEPSS 0.4%