Weaknesses of type CWE-200

4,980 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-61304MEDIUMVulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.3%CVE-2026-62525MEDIUMVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supported versions that EPSS 0.3%CVE-2025-24281MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive usEPSS 0.3%CVE-2026-62519MEDIUMVulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that arEPSS 0.3%CVE-2026-91992HIGHTornado before 6.5.7 Credential Leak via Handle ReuseEPSS 0.3%CVE-2026-12117MEDIUMImproper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enuEPSS 0.3%CVE-2025-62524MEDIUMPILOS Exposes PHP versionEPSS 0.3%CVE-2025-30435MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may beEPSS 0.3%CVE-2025-53840LOWIcinga DB Web Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityEPSS 0.3%CVE-2025-51643LOWMeitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protEPSS 0.3%CVE-2021-20320—A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with sEPSS 0.3%CVE-2025-24282MEDIUMA library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to modifEPSS 0.3%CVE-2024-11994MEDIUMAPM Server Insertion of Sensitive Information into Log FileEPSS 0.3%CVE-2026-23597MEDIUMUnauthenticated Information Disclosure in application API allows sensitive system information exposureEPSS 0.3%CVE-2022-32825MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tEPSS 0.3%CVE-2022-27575LOWInformation exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app inforEPSS 0.3%CVE-2026-84127MEDIUMInformation disclosure in the WebExtensions component in Firefox for AndroidEPSS 0.3%CVE-2026-78896MEDIUMInformation leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a craEPSS 0.3%CVE-2026-9955MEDIUMInappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via EPSS 0.3%CVE-2026-7999MEDIUMInappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive informaEPSS 0.3%