Weaknesses of type CWE-200

4,979 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2021-25464LOWAn improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak.EPSS 0.3%CVE-2025-30443MEDIUMA privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sequoia 15.5, macOS Sonoma 1EPSS 0.3%CVE-2022-28764LOWLocal information exposure in Zoom ClientsEPSS 0.3%CVE-2026-60919LOWVulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.3%CVE-2026-60352LOWVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected areEPSS 0.3%CVE-2026-39943MEDIUMDirectus exposes sensitive fields in revision historyEPSS 0.3%CVE-2026-60853LOWVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.3%CVE-2026-60354LOWVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that aEPSS 0.3%CVE-2026-61015LOWVulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2026-61104LOWVulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported vEPSS 0.3%CVE-2026-101146MEDIUMEleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit information disclosureEPSS 0.3%CVE-2021-3798—A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObjEPSS 0.3%CVE-2026-22203MEDIUMwpDiscuz before 7.6.47 - Options Export Leaks OAuth Secrets in PlaintextEPSS 0.3%CVE-2025-24283MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.EPSS 0.3%CVE-2026-15758MEDIUM3D FlipBook <= 1.16.20 - Unauthenticated Sensitive Information Exposure in 'id' ParameterEPSS 0.3%CVE-2025-12148MEDIUMUnauthorized access to fields protected by Field Masking (FM) for fields of type IPEPSS 0.3%CVE-2025-65090MEDIUMXWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONServiceEPSS 0.3%CVE-2024-52975CRITICALFleet Server sensitive information exposure via logsEPSS 0.3%CVE-2025-43018MEDIUMCertain HP LaserJet Pro Printers – Potential Information DisclosureEPSS 0.3%CVE-2025-12147MEDIUMUnauthorized access to fields protected by Field-Level Security (FLS) when those fields are members of an objectEPSS 0.3%