Weaknesses of type CWE-200

4,989 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-87531LOWInformation leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtaiEPSS 0.2%CVE-2025-10281MEDIUMInsecure URL Handling in git_clone Leading to Leaked API KeyEPSS 0.2%CVE-2025-24220MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.9. An app may bEPSS 0.2%CVE-2026-11168MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendereEPSS 0.2%CVE-2024-39527MEDIUMJunos OS: SRX Series: Low privileged user able to access sensitive information on file systemEPSS 0.2%CVE-2026-11209MEDIUMInappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendererEPSS 0.2%CVE-2024-40838LOWA privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15. A malicious app mayEPSS 0.2%CVE-2026-11180MEDIUMInappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafteEPSS 0.2%CVE-2026-11271MEDIUMInappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage iEPSS 0.2%CVE-2026-11203MEDIUMInappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via aEPSS 0.2%CVE-2026-50169MEDIUMAngular Service Worker Policy-Bypass & Credential-Stripping VulnerabilitiesEPSS 0.2%CVE-2026-20164MEDIUMSensitive Information Disclosure through Improper Access Control in Splunk EnterpriseEPSS 0.2%CVE-2026-25135MEDIUMOpenEMR's location resource for Group.$export operation returns entire patient/user population contact informationEPSS 0.2%CVE-2024-42179LOWHCL MyXalytics is affected by sensitive information disclosure vulnerabilityEPSS 0.2%CVE-2025-11377MEDIUMList category posts <= 0.92.0 - Authenticated (Contributor+) Information ExposureEPSS 0.2%CVE-2022-36878LOWExposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via log.EPSS 0.2%CVE-2026-100703HIGHKyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.LibEPSS 0.2%CVE-2025-24144MEDIUMAn information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.EPSS 0.2%CVE-2021-21534MEDIUMDell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vuEPSS 0.2%CVE-2025-43215MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may result iEPSS 0.2%