Weaknesses of type CWE-200

4,975 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-87565MEDIUMInformation leak in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information EPSS 0.3%CVE-2026-13810MEDIUMInappropriate implementation in Input in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensiEPSS 0.3%CVE-2026-79291MEDIUMInformation leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTMLEPSS 0.3%CVE-2023-5579LOWyhz66 Sandbox User Data information disclosureEPSS 0.3%CVE-2025-12363CRITICALEmail Password DisclosureEPSS 0.3%CVE-2025-15482MEDIUMChapa Payment Gateway Plugin for WooCommerce <= 1.0.3 - Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2026-14188LOWEasy Appointments < 3.12.28 - Contributor+ Customer Data DisclosureEPSS 0.3%CVE-2026-92423LOWMeow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_postsEPSS 0.3%CVE-2025-24244MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, mEPSS 0.3%CVE-2026-35142LOWHCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability.EPSS 0.3%CVE-2025-58458MEDIUMIn Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the EPSS 0.3%CVE-2024-9945MEDIUMLimited Information Disclosure in GoAnywhere MFT Prior to 7.7.0EPSS 0.3%CVE-2026-19858HIGHJetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosure via Dynamic PresetEPSS 0.3%CVE-2026-87836LOWComments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via ExportEPSS 0.3%CVE-2026-84903LOWKing Addons for Elementor < 51.1.81 - Contributor+ Private Post Content Disclosure via kng_maintenance_page ShortcodeEPSS 0.3%CVE-2026-61240HIGHVulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eSettlements). The supporEPSS 0.3%CVE-2026-84745LOWThe Events Calendar &lt; 6.17.3.1 - Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST APIEPSS 0.3%CVE-2026-19406LOWEasy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via REST Appointments ListingEPSS 0.3%CVE-2026-62518HIGHVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.3%CVE-2026-84926LOWEmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST RouteEPSS 0.3%