Weaknesses of type CWE-200

4,974 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-44431HIGHurllib3: Sensitive headers forwarded across origins in proxied low-level redirectsEPSS 0.3%CVE-2026-88059MEDIUMAngular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`EPSS 0.3%CVE-2026-64778MEDIUMThe issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26EPSS 0.3%CVE-2026-62286MEDIUMDozzle label filters do not restrict container event and statistics streamsEPSS 0.3%CVE-2023-24010HIGHData Distribution Service (DDS) Chain of Trust (CoT) violation in Fast DDSEPSS 0.3%CVE-2024-23207MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 1EPSS 0.3%CVE-2026-91766MEDIUMCross-origin credential leak in HTTP stream wrapper redirectsEPSS 0.3%CVE-2026-100418MEDIUMFlame through 2.4.0 Information Exposure via GET /api/configEPSS 0.3%CVE-2023-24011HIGHData Distribution Service (DDS) Chain of Trust (CoT) violation vulnerability in Cyclone DDSEPSS 0.3%CVE-2025-5064MEDIUMInappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin EPSS 0.3%CVE-2025-54290MEDIUMProject Existence Disclosure via Error Handling in LXD Image ExportEPSS 0.3%CVE-2026-71087MEDIUMVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.3%CVE-2026-70911MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2026-46790MEDIUMVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that EPSS 0.3%CVE-2026-60260MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.3%CVE-2026-60237MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.EPSS 0.3%CVE-2026-46841MEDIUMVulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitableEPSS 0.3%CVE-2026-60156MEDIUMVulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulneraEPSS 0.3%CVE-2026-46830MEDIUMVulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitablEPSS 0.3%CVE-2024-27897HIGHInput verification vulnerability in the call module. Impact: Successful exploitation of this vulnerability may affect service confidentialitEPSS 0.3%