Weaknesses of type CWE-200

4,988 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-60864MEDIUMVulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions tEPSS 0.2%CVE-2022-36877LOWExposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in ChinaEPSS 0.2%CVE-2024-40842MEDIUMAn issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15. An app may be able to accEPSS 0.2%CVE-2021-25432—Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.EPSS 0.2%CVE-2026-77320MEDIUMTREK: Public trip share link ignores the `share_map` permission server-side (client-enforced authorization → itinerary/location disclosure)EPSS 0.2%CVE-2026-20137LOWRisky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vulnerability in Splunk EnterpriseEPSS 0.2%CVE-2021-25403—Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) aEPSS 0.2%CVE-2021-4135—A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way user uses BPF for theEPSS 0.2%CVE-2023-29116MEDIUMPHP Information Disclosure in Enel X JuiceBoxEPSS 0.2%CVE-2026-79059LOWInformation leak in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obEPSS 0.2%CVE-2026-87531LOWInformation leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtaiEPSS 0.2%CVE-2025-10282MEDIUMGitLab Domain Confusion in gitlab Leaks API KeyEPSS 0.2%CVE-2025-46388MEDIUMCWE-200 Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.2%CVE-2026-87521LOWInformation leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtEPSS 0.2%CVE-2026-79034LOWInformation leak in CORS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak EPSS 0.2%CVE-2026-87451LOWInformation leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to EPSS 0.2%CVE-2021-32002MEDIUMSiteManager troubleshooter allows access without authentication from local networkEPSS 0.2%CVE-2025-8866MEDIUMYugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attackEPSS 0.2%CVE-2024-44129MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Ventura 13.7. An app may be able to leak sensitEPSS 0.2%CVE-2023-23511—The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, iOS 16.3 and iPadOSEPSS 0.2%