Weaknesses of type CWE-200

4,975 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-79018MEDIUMInformation leak in FoldableAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a craEPSS 0.3%CVE-2026-78893MEDIUMInformation leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML EPSS 0.3%CVE-2026-18005MEDIUMInappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive infoEPSS 0.3%CVE-2026-95327MEDIUMInformation leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a craftedEPSS 0.3%CVE-2026-79293MEDIUMInformation leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafteEPSS 0.3%CVE-2026-84348MEDIUMInformation leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive informationEPSS 0.3%CVE-2026-79024MEDIUMInformation leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crEPSS 0.3%CVE-2024-5880MEDIUMHide My Site <= 2.2 - Unauthenticated Information ExposureEPSS 0.3%CVE-2026-14146MEDIUMInappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafteEPSS 0.3%CVE-2026-79124MEDIUMInformation leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information viEPSS 0.3%CVE-2026-87437MEDIUMInformation leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTMEPSS 0.3%CVE-2026-55651HIGHEasy!Appointments Vulnerable to Appointments Takeover via Excessive Data ExposureEPSS 0.3%CVE-2026-87454MEDIUMInformation leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive informatiEPSS 0.3%CVE-2026-79075MEDIUMInformation leak in Geolocation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain seEPSS 0.3%CVE-2026-18001MEDIUMInappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive infoEPSS 0.3%CVE-2026-17892MEDIUMInappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive infoEPSS 0.3%CVE-2026-95336MEDIUMInformation leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering toEPSS 0.3%CVE-2026-9912MEDIUMInappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensEPSS 0.3%CVE-2026-87545MEDIUMInformation leak in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leakEPSS 0.3%CVE-2026-87565MEDIUMInformation leak in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information EPSS 0.3%