Weaknesses of type CWE-200

5,020 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2022-33724LOWExposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via lEPSS 0.1%CVE-2025-15065HIGHData Exposure in Kings Information & Network KESS EnterpriseEPSS 0.1%CVE-2026-106330—Information leak in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTMLEPSS —CVE-2026-106342HIGHInformation leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a craftedEPSS —CVE-2026-106254MEDIUMInformation leak in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information viEPSS —CVE-2026-97626—Gitea profile feed disclosure bypassing user visibilityEPSS —CVE-2026-104963MEDIUMPlane: Workspace cycle and module endpoints missing project-membership filter expose private project metadata to any workspace memberEPSS —CVE-2026-105684MEDIUMPenpot: Share-link page-scope escape — comment RPCs leak comment content, author identity, and all page-ids for pages outside the share scopeEPSS —CVE-2026-106220HIGHInformation leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafteEPSS —CVE-2026-63270MEDIUMEnvironment/ini-file leaksEPSS —CVE-2026-106256HIGHInformation leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering EPSS —CVE-2026-63268MEDIUMLFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db hrefEPSS —CVE-2026-106242—Information leak in Omnibox in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering toEPSS —CVE-2026-106214MEDIUMInformation leak in Proxy in Google Chrome on on Windows prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive informationEPSS —CVE-2026-106348—Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted EPSS —CVE-2026-105853HIGHPayload: Token refresh and password reset responses may expose restricted user fieldsEPSS —CVE-2026-105635HIGHPlane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without TokenEPSS —CVE-2026-106120MEDIUMLiquidJS: ownPropertyOnly bypass for inherited array indices in first/last/join/reverse/slice/compact, `.first`/`.last`, negative index, and for-loop iterationEPSS —CVE-2026-106459HIGHBackstage: Improper input validation in Sentry scaffolder actionsEPSS —CVE-2026-63269MEDIUMLFI and GET SSRF via GStreamer and HLS playlistsEPSS —