Weaknesses of type CWE-200

4,980 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2023-45816LOWUnread bookmark reminder notifications that the user cannot access can be seenEPSS 0.3%CVE-2024-44685MEDIUMTitan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwordEPSS 0.3%CVE-2026-9656MEDIUMHubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized ScriptEPSS 0.3%CVE-2020-6653LOWSensitive date stored in logcat fileEPSS 0.3%CVE-2026-105120MEDIUMOpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST EndpointEPSS 0.3%CVE-2026-14049MEDIUMInappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer proceEPSS 0.3%CVE-2026-61214LOWVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are EPSS 0.3%CVE-2021-21512HIGHDell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally authenticated high priviEPSS 0.3%CVE-2022-0987—A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a localEPSS 0.3%CVE-2023-38296HIGHVarious software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be accessed by any local EPSS 0.3%CVE-2023-36476HIGH`calamares-nixos-extensions` LUKS keyfile exposureEPSS 0.3%CVE-2021-32007LOWMissing security header: Referrer-Policy URLEPSS 0.3%CVE-2026-60950LOWVulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2025-13804MEDIUMnutzam NutzBoot Ethereum Wallet EthModule.java information disclosureEPSS 0.3%CVE-2026-62525MEDIUMVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supported versions that EPSS 0.3%CVE-2026-61304MEDIUMVulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.3%CVE-2025-11406MEDIUMkaifangqian kaifangqian-base SysUserController.java getAllUsers information disclosureEPSS 0.3%CVE-2026-62524MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affEPSS 0.3%CVE-2026-91992HIGHTornado before 6.5.7 Credential Leak via Handle ReuseEPSS 0.3%CVE-2025-65957HIGHCore Bot is Leaking Sensitive Credentials in Logs, Errors, and MessagesEPSS 0.3%