Weaknesses of type CWE-200

4,993 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-21615MEDIUMAAT allows data exfiltration by other apps installed on the same deviceEPSS 0.2%CVE-2025-67399MEDIUMAn issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive information via the UEPSS 0.2%CVE-2026-21758LOWHCL Hive is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2024-41629MEDIUMAn issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plainteEPSS 0.2%CVE-2025-9907MEDIUMEvent-driven-ansible: event stream test mode exposes sensitive headers in aap edaEPSS 0.2%CVE-2026-46816LOWVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affecEPSS 0.2%CVE-2026-46874LOWVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2022-24410MEDIUM Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledgEPSS 0.2%CVE-2026-64755MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPaEPSS 0.2%CVE-2023-44187MEDIUMJunos OS Evolved: 'file copy' CLI command can disclose password to shell usersEPSS 0.2%CVE-2026-60160LOWVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-46977LOWVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affecEPSS 0.2%CVE-2026-47043LOWVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-46815LOWVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affecEPSS 0.2%CVE-2025-60892MEDIUMAn issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' EPSS 0.2%CVE-2026-22006MEDIUMVulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapshot). The supported EPSS 0.2%CVE-2026-60607MEDIUMVulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: FM Need Analysis Calculator). The supEPSS 0.2%CVE-2023-46183MEDIUMIBM PowerVM Hypervisor information disclosureEPSS 0.2%CVE-2026-20672MEDIUMAn information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8EPSS 0.2%CVE-2023-21449MEDIUMImproper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive informaEPSS 0.2%