Weaknesses of type CWE-200

5,017 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2025-10222MEDIUMSensitive Information Disclosure in Diagnostic Dumps in AxxonSoft Axxon One VMSEPSS 0.1%CVE-2026-41980MEDIUMPermission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may affect service confidEPSS 0.1%CVE-2026-22007LOWVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: SecuritEPSS 0.1%CVE-2026-49301MEDIUMPermission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.1%CVE-2026-78957MEDIUMInformation leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a EPSS 0.1%CVE-2022-39856MEDIUMImproper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allows local attackers to access call informEPSS 0.1%CVE-2024-58252MEDIUMVulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this vulnerability may aEPSS 0.1%CVE-2026-79146MEDIUMInformation leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data viEPSS 0.1%CVE-2026-20681LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26.3. An app may be aEPSS 0.1%CVE-2025-66963MEDIUMAn issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.htmlEPSS 0.1%CVE-2022-22075MEDIUMInformation Exposure in GraphicsEPSS 0.1%CVE-2026-73732MEDIUMLocal Authenticated Sensitive Information Disclosure in HPE Networking Fabric ComposerEPSS 0.1%CVE-2025-8305MEDIUMInformation Disclosure in Identity Agent Debug FilesEPSS 0.1%CVE-2025-8304MEDIUMInformation Disclosure in Identity Agent Registry KeysEPSS 0.1%CVE-2025-65951HIGHInside Track / Entropy Derby Timelock Encryption Bypassed via Pre-Computed VDF Output LeakageEPSS 0.1%CVE-2026-20737MEDIUMExposure of sensitive information to an unauthorized actor for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: DeviceEPSS 0.1%CVE-2024-53011HIGHPermissions, Privileges, and Access Controls in Video Analytics and ProcessingEPSS 0.1%CVE-2022-39914MEDIUMExposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows loEPSS 0.1%CVE-2022-39903MEDIUMImproper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.EPSS 0.1%CVE-2026-73738MEDIUMAuthenticated Sensitive Information Disclosure in HPE Networking Fabric ComposerEPSS 0.1%