Weaknesses of type CWE-200

4,952 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-2747MEDIUMPGP Mixed Plaintext and Encrypted ContentEPSS 0.4%CVE-2026-45378HIGHDecidim: Verification documents can be downloaded through reusable linksEPSS 0.4%CVE-2011-4327MEDIUMssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, whEPSS 0.4%CVE-2025-30218LOWNext.js may leak x-middleware-subrequest-id to external hostsEPSS 0.4%CVE-2026-49269HIGHApple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run aEPSS 0.4%CVE-2026-83424HIGHVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper). Supported versions that are affeEPSS 0.4%CVE-2026-17542HIGHBit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connectorEPSS 0.4%CVE-2026-86419HIGHMISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed Redirects and TAXII DiscoveryEPSS 0.4%CVE-2026-16594HIGHWP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key DisclosureEPSS 0.4%CVE-2026-49187HIGHHard-coded APK Resource Credentials & SceptersEPSS 0.4%CVE-2026-49193HIGHPublicly Readable AWS S3 Telemetry BucketsEPSS 0.4%CVE-2026-59499HIGHPriority – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.4%CVE-2026-65881HIGHJoomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1EPSS 0.4%CVE-2026-50210MEDIUMWeak Static Cryptographic Initialization VectorsEPSS 0.4%CVE-2026-83167HIGHVulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are afEPSS 0.4%CVE-2022-0494—A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows EPSS 0.4%CVE-2026-7542MEDIUMSlider Revolution 7.0 - 7.0.10 - Authenticated (Subscriber+) Sensitive Information DisclosureEPSS 0.4%CVE-2026-65430HIGHJoomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extensionEPSS 0.4%CVE-2026-83326HIGHVulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affecteEPSS 0.4%CVE-2026-23983LOWApache Superset: Sensitive Data Exposure via REST API (disabled by default)EPSS 0.4%