Weaknesses of type CWE-200

4,993 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-20158MEDIUMCisco Video Phone 8875 and Desk Phone 9800 Series Information Disclosure VulnerabilityEPSS 0.2%CVE-2024-1591LOWPrivilege Management for Windows < 24.1 Information LeakEPSS 0.2%CVE-2026-60318LOWVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that arEPSS 0.2%CVE-2024-57096MEDIUMAn issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.EPSS 0.2%CVE-2025-43360MEDIUMThe issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fields may be unintentionally revealed.EPSS 0.2%CVE-2026-24198MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memoryEPSS 0.2%CVE-2024-23563LOWHCL Connections Docs is vulnerable to a sensitive information disclosureEPSS 0.2%CVE-2026-60405LOWVulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The suppoEPSS 0.2%CVE-2026-44276MEDIUMDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulneraEPSS 0.2%CVE-2026-83277HIGHVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.2%CVE-2026-20166MEDIUMSensitive Information Disclosure in Discover Splunk Observability Cloud app for Splunk EnterpriseEPSS 0.2%CVE-2026-84626LOWAn information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPEPSS 0.2%CVE-2026-65371LOWThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15EPSS 0.2%CVE-2026-46406MEDIUMClaude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File WriteEPSS 0.2%CVE-2026-86883MEDIUMA privacy issue was addressed with improved handling of files. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27. An app may be able EPSS 0.2%CVE-2025-61679HIGHAnyquery Unauthenticated Access Vulnerability Exposes Private Integration DataEPSS 0.2%CVE-2026-15642LOWInsertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.EPSS 0.2%CVE-2025-31982LOWHCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directlEPSS 0.2%CVE-2026-28877MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOEPSS 0.2%CVE-2026-49356LOWBabel: Arbitrary File Read via sourceMappingURL Comment in @babel/coreEPSS 0.2%