Weaknesses of type CWE-200

4,993 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2024-42508MEDIUMThis vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.EPSS 0.2%CVE-2023-32476MEDIUM Dell Hybrid Client version 2.0 contains a Sensitive Data Exposure vulnerability. An unauthenticated malicious user on the device can accessEPSS 0.2%CVE-2025-8886MEDIUMAuthorization Bypass in Usta Information Systems' Aybs InteraktifEPSS 0.2%CVE-2026-35143LOWHCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.EPSS 0.2%CVE-2025-9036HIGHRockwell Automation FactoryTalk® Action Manager v1.0.0 Runtime VulnerabilityEPSS 0.2%CVE-2026-17515MEDIUMMLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_itemEPSS 0.2%CVE-2021-26279MEDIUMInformation disclosure vulnerability in Weather moduleEPSS 0.2%CVE-2026-84576MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app mayEPSS 0.2%CVE-2025-64312MEDIUMPermission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.2%CVE-2026-90503MEDIUMChengdu Qilu Technology Ludashi ComputerZ_x64.sys sub_11008 information disclosureEPSS 0.2%CVE-2026-73230MEDIUMEnte: 2of3 cards v1 contain a checksum that enables offline guessing of low-entropy secretsEPSS 0.2%CVE-2025-33045HIGHLegacy Serial Redirection SMRAM VulnerabilitiesEPSS 0.2%CVE-2021-22529MEDIUMSensitive Data Exposure leaks potential information in NetIQ Advance AuthenticationEPSS 0.2%CVE-2026-20674MEDIUMA privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access EPSS 0.2%CVE-2025-43345MEDIUMA correctness issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS SequoiaEPSS 0.2%CVE-2026-43756MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. AnEPSS 0.2%CVE-2025-31985LOWHCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” headerEPSS 0.2%CVE-2026-102267HIGHPyJWT: PyJWKClient follows redirects when fetching JWKSEPSS 0.2%CVE-2026-84586MEDIUMAn information disclosure issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, watchOS 27. A malEPSS 0.2%CVE-2026-86887LOWA privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS 27EPSS 0.2%