Weaknesses of type CWE-200

4,981 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-17928MEDIUMInappropriate implementation in DataTransfer in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data viaEPSS 0.3%CVE-2022-27575LOWInformation exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app inforEPSS 0.3%CVE-2026-79274MEDIUMInformation leak in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML pagEPSS 0.3%CVE-2026-84127MEDIUMInformation disclosure in the WebExtensions component in Firefox for AndroidEPSS 0.3%CVE-2024-27806MEDIUMThis issue was addressed with improved environment sanitization. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17EPSS 0.3%CVE-2026-87495MEDIUMInformation leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leaEPSS 0.3%CVE-2022-32825MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tEPSS 0.3%CVE-2026-23597MEDIUMUnauthenticated Information Disclosure in application API allows sensitive system information exposureEPSS 0.3%CVE-2026-79095MEDIUMInformation leak in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTMEPSS 0.3%CVE-2026-79144MEDIUMInformation leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML paEPSS 0.3%CVE-2024-52589LOWModerators can view Screened emails even when the “moderators view emails” option is disabled in DiscourseEPSS 0.3%CVE-2026-50025MEDIUMMousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie stateEPSS 0.3%CVE-2026-56578LOWHCL MyCloud was affected by Server Version DisclosureEPSS 0.3%CVE-2025-12732MEDIUMWP Import – Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticated (Author+) Sensitive Information ExposureEPSS 0.3%CVE-2021-20256—A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hEPSS 0.3%CVE-2025-68429HIGHStorybook manager bundle may expose environment variables during buildEPSS 0.3%CVE-2026-40203LOWWhen IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacEPSS 0.3%CVE-2026-96255HIGHPayments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via Debug LogEPSS 0.3%CVE-2026-19715HIGHWP OAuth Server < 6.3.1 - Unauthenticated OAuth Token and User Data Disclosure via Debug Log FileEPSS 0.3%CVE-2021-22276MEDIUMfree@home System Access Point FW integrity check can be bypassed.EPSS 0.3%