Weaknesses of type CWE-200

4,979 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-102002LOWOtter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard WidgetEPSS 0.3%CVE-2026-23743MEDIUMDiscourse allows permalinks to restricted resources to leak resource slugs to unauthorized usersEPSS 0.3%CVE-2026-27467LOWBigBlueButton: Audio from participants to the server initially unmutedEPSS 0.3%CVE-2026-87435MEDIUMInformation leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer proceEPSS 0.3%CVE-2026-95367MEDIUMInformation leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process EPSS 0.3%CVE-2024-45799HIGHJavascript Injection in Vending Info/Buyers Info Module in FluxCPEPSS 0.3%CVE-2026-79074MEDIUMInformation leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obEPSS 0.3%CVE-2025-12149MEDIUMUnauthorized access to documents protected by Document-Level Security (DLS), when Signals watches include a search query involving protected documentsEPSS 0.3%CVE-2025-59031MEDIUMDovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can useEPSS 0.3%CVE-2025-7426CRITICALMINOVA TTA Information Disclosure and Credential ExposureEPSS 0.3%CVE-2026-87439MEDIUMInformation leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer processEPSS 0.3%CVE-2020-27290—In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilator allows attackers wEPSS 0.3%CVE-2026-79001MEDIUMInformation leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer pEPSS 0.3%CVE-2026-79220MEDIUMInformation leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obEPSS 0.3%CVE-2025-70963HIGHGophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly insEPSS 0.3%CVE-2022-0553MEDIUMPossible to retrieve uncrypted firmware imageEPSS 0.3%CVE-2021-21364MEDIUMGenerated Code Contains Local Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-70974MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2025-46720LOWKeystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fieldsEPSS 0.3%CVE-2025-20379LOWRisky command safeguards bypass using the “/services/streams/search“ REST endpoint through “q“ parameter in Splunk EnterpriseEPSS 0.3%