Weaknesses of type CWE-200

4,997 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-20619MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be ablEPSS 0.1%CVE-2025-67499MEDIUMCNI Plugins Portmap nftables backend intercepts non-local trafficEPSS 0.1%CVE-2026-80356HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulEPSS 0.1%CVE-2026-61303LOWVulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are afEPSS 0.1%CVE-2026-60891LOWVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%CVE-2022-44746LOWSensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office EPSS 0.1%CVE-2026-60913LOWVulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.1%CVE-2025-40768HIGHA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application exposes aEPSS 0.1%CVE-2025-48464MEDIUMExposure of Sensitive InformationEPSS 0.1%CVE-2026-45726HIGHOmni: Reader-level users can retrieve imported cluster CA keys via ResourceServiceEPSS 0.1%CVE-2025-58061MEDIUMOpenEBS Local PV RawFile persistent volume data is world readableEPSS 0.1%CVE-2025-43437LOWAn information disclosure issue was addressed with improved privacy controls. This issue is fixed in iOS 26.1 and iPadOS 26.1. An app may beEPSS 0.1%CVE-2025-20290MEDIUMCisco NXOS Software Sensitive Log Information Disclosure VulnerabilityEPSS 0.1%CVE-2026-47514HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause exposure of kernEPSS 0.1%CVE-2025-31984LOWHCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” headerEPSS 0.1%CVE-2026-20648MEDIUMA privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Tahoe 26.3. A malicious app mayEPSS 0.1%CVE-2025-9381LOWFNKvision Y215 CCTV Camera wpa_supplicant.conf information disclosureEPSS 0.1%CVE-2026-24916MEDIUMIdentity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service EPSS 0.1%CVE-2026-75587LOWPlaintext pre-auth secret exposure via Desktop App diagnostics reportEPSS 0.1%CVE-2026-0005MEDIUMIn onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction witEPSS 0.1%