Weaknesses of type CWE-200

4,993 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-38688MEDIUMIn telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privEPSS 0.2%CVE-2026-83279MEDIUMVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.2%CVE-2026-86878MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to access seEPSS 0.2%CVE-2026-83274MEDIUMVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.2%CVE-2026-63278MEDIUMPackage URLs can be used to exfiltrate arbitrary INI file values and environment variablesEPSS 0.1%CVE-2026-42283HIGHDevSpace UI Server WebSocket CheckOrigin does not validate sourceEPSS 0.1%CVE-2026-90811MEDIUMcosmicstack-labs mercury-agent Shell Permission Manifest permissions.ts PermissionManager.checkShellCommand information disclosureEPSS 0.1%CVE-2026-16398HIGHSite isolation issue in the Graphics componentEPSS 0.1%CVE-2026-90895HIGHMISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal InjectionEPSS 0.1%CVE-2026-84530LOWAn information disclosure issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iEPSS 0.1%CVE-2024-39600MEDIUM[CVE-2024-39600] Information Disclosure vulnerability in SAP GUI for WindowsEPSS 0.1%CVE-2025-20611MEDIUMExposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow aEPSS 0.1%CVE-2025-8887MEDIUMIDOR in Usta Information Systems' Aybs InteraktifEPSS 0.1%CVE-2026-79780MEDIUMrclone before v1.75.0 Credential Exposure via S3 RedirectEPSS 0.1%CVE-2026-60886HIGHVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%CVE-2022-39904LOWExposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the NetEPSS 0.1%CVE-2026-82810MEDIUMextension.vn 2FA Authenticator Extension Background Service Worker chrome.runtime.onMessageExternal.addListener information disclosureEPSS 0.1%CVE-2026-47165MEDIUMImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication modelEPSS 0.1%CVE-2019-1589MEDIUMCisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Unmeasured Boot VulnerabilityEPSS 0.1%CVE-2026-41960MEDIUMPermission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%