Weaknesses of type CWE-200

4,991 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-84359LOWInformation leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak EPSS 0.2%CVE-2025-31250MEDIUMAn information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able EPSS 0.2%CVE-2025-11645LOWTomofun Furbo Mobile App Authentication Token sensitive informationEPSS 0.2%CVE-2026-49449LOWJoplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on WindowsEPSS 0.2%CVE-2023-28203MEDIUMThe issue was addressed with improved checks. This issue is fixed in Apple Music 4.2.0 for Android. An app may be able to access contacts.EPSS 0.2%CVE-2026-4040MEDIUMOpenClaw File Existence tools.exec.safeBins information exposureEPSS 0.2%CVE-2024-54475LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma EPSS 0.2%CVE-2026-81870LOWOpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logsEPSS 0.2%CVE-2026-79252MEDIUMInformation leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafteEPSS 0.2%CVE-2025-46820HIGHphpgt/Dom exposes the GITHUB_TOKEN in Dom workflow run artifactEPSS 0.2%CVE-2025-55165HIGHAutocaliweb Exposure of Sensitive Information to an Unauthorized Actor in `config_sql.py`EPSS 0.2%CVE-2025-14553HIGHPassword Hash Leak Could Lead to Unauthorized Access on Tapo App via Local NetworkEPSS 0.2%CVE-2026-20141MEDIUMImproper Access Control in Splunk Monitoring Console AppEPSS 0.2%CVE-2024-20920LOWVulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. EasilEPSS 0.2%CVE-2026-45536MEDIUMNetty: Unix-socket fd receive leaks descriptors when peer sends two at onceEPSS 0.2%CVE-2023-1633MEDIUMInsecure barbican configuration file leaking credentialEPSS 0.2%CVE-2026-60413HIGHVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version EPSS 0.2%CVE-2026-13611MEDIUMKiviCare – Clinic & Patient Management System (EHR) < 4.5.5 - Unauthenticated Patient Data DisclosureEPSS 0.2%CVE-2026-55406MEDIUMBuffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in DerefEPSS 0.2%CVE-2026-60414HIGHVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version EPSS 0.2%