Weaknesses of type CWE-200

4,991 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-74934HIGHSite isolation issue in the Graphics: CanvasWebGL componentEPSS 0.2%CVE-2024-52966LOWAn exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause informaEPSS 0.2%CVE-2023-41987MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access sensitive user data.EPSS 0.2%CVE-2024-54547MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app mEPSS 0.2%CVE-2023-40411MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Sonoma 14. An app may be able to access user-sensitive EPSS 0.2%CVE-2025-25209MEDIUMRhcl: sharedsecretref can be used to leak secrets severityEPSS 0.2%CVE-2024-56443MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2025-24142MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma EPSS 0.2%CVE-2022-1662—In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Manager user password EPSS 0.2%CVE-2026-53682MEDIUMPki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hostsEPSS 0.2%CVE-2026-96869MEDIUMInformation disclosure in the Networking componentEPSS 0.2%CVE-2026-67172LOWHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2023-4177LOWEmpowerID Multi-Factor Authentication Code information disclosureEPSS 0.2%CVE-2026-50184MEDIUMAngular: Request Credential & Cache Policy Stripping in Angular Service WorkerEPSS 0.2%CVE-2026-101265LOWIntelbras TIP 125i Básico sensitive information in sourceEPSS 0.2%CVE-2026-16983MEDIUMGutentor < 4.0.6 - Subscriber+ Password Protected Post Password Disclosure via REST APIEPSS 0.2%CVE-2021-20260—A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with EPSS 0.2%CVE-2022-25828LOWInformation Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access password information ofEPSS 0.2%CVE-2026-90441HIGHFireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant BEPSS 0.2%CVE-2022-25827LOWInformation Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information ofEPSS 0.2%