Weaknesses of type CWE-200

4,985 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2021-47403HIGHipack: ipoctal: fix module reference leakEPSS 0.2%CVE-2024-36910HIGHuio_hv_generic: Don't free decrypted memoryEPSS 0.2%CVE-2023-5718MEDIUMThe Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessage()` API. By creatiEPSS 0.2%CVE-2026-16400HIGHInformation disclosure in the DOM: Security componentEPSS 0.2%CVE-2026-60930LOWVulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.2%CVE-2024-40804MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A malicious application may be able to access privatEPSS 0.2%CVE-2026-60922LOWVulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.2%CVE-2026-11182MEDIUMInappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafteEPSS 0.2%CVE-2026-60339LOWVulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported versioEPSS 0.2%CVE-2025-24138MEDIUMThis issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13EPSS 0.2%CVE-2026-60939LOWVulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that EPSS 0.2%CVE-2026-60620MEDIUMVulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management). The supportEPSS 0.2%CVE-2026-56579LOWHCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor.EPSS 0.2%CVE-2024-54473MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15. An app may be able to acEPSS 0.2%CVE-2025-41066MEDIUMDisclosure of sensitive information in Horde GroupwareEPSS 0.2%CVE-2026-28820MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.EPSS 0.2%CVE-2026-0860HIGHMali GPU Kernel Driver allows access to sensitive kernel informationEPSS 0.2%CVE-2024-28238LOWSession Token in URL in directusEPSS 0.2%CVE-2026-17902LOWInappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin dataEPSS 0.2%CVE-2021-3736—A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O EPSS 0.2%