Weaknesses of type CWE-200

4,979 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-35145LOWHCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability.EPSS 0.3%CVE-2022-43539MEDIUM A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position tEPSS 0.3%CVE-2026-16373HIGHInformation disclosure in the Privacy component in Firefox for AndroidEPSS 0.3%CVE-2023-47298MEDIUMAn issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain informaEPSS 0.3%CVE-2026-62528MEDIUMVulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Supported versions that arEPSS 0.3%CVE-2026-62527MEDIUMVulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supported versions that EPSS 0.3%CVE-2020-10698—A flaw was found in Ansible Tower when running jobs. This flaw allows an attacker to access the stdout of the executed jobs which are run frEPSS 0.3%CVE-2022-34674MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical paEPSS 0.3%CVE-2025-64179MEDIUMlakeFS: Unauthenticated access to API usage metricsEPSS 0.3%CVE-2025-13973MEDIUMStickEasy Protected Contact Form <= 1.0.1 - Unauthenticated Information DisclosureEPSS 0.3%CVE-2026-61294MEDIUMVulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizations). SupportEPSS 0.3%CVE-2026-61266MEDIUMVulnerability in the Oracle Supply Chain Globalization product of Oracle E-Business Suite (component: Copy Inventory Organization). SupportEPSS 0.3%CVE-2025-63579HIGHUnauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that enEPSS 0.3%CVE-2026-49288MEDIUMStatamic CMS missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resourcesEPSS 0.3%CVE-2026-86417MEDIUMMISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized UsersEPSS 0.3%CVE-2026-61103MEDIUMVulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version tEPSS 0.3%CVE-2026-61123MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.3%CVE-2025-9987MEDIUMBroadstreet <= 1.53.1 - Authenticated (Subscriber+) Information DisclosureEPSS 0.3%CVE-2026-86418LOWMISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized UsersEPSS 0.3%CVE-2026-42392MEDIUMAn attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the erEPSS 0.3%