Weaknesses of type CWE-200

5,021 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2026-106220HIGHInformation leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafteEPSS —CVE-2026-106330—Information leak in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTMLEPSS —CVE-2026-106348—Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted EPSS —CVE-2026-105853HIGHPayload: Token refresh and password reset responses may expose restricted user fieldsEPSS —CVE-2026-106237—Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTMEPSS —CVE-2026-104963MEDIUMPlane: Workspace cycle and module endpoints missing project-membership filter expose private project metadata to any workspace memberEPSS —CVE-2026-105635HIGHPlane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without TokenEPSS —CVE-2026-106321—Information leak in Editing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitivEPSS —CVE-2026-105752LOWvLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracleEPSS —CVE-2026-106214MEDIUMInformation leak in Proxy in Google Chrome on on Windows prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive informationEPSS —CVE-2026-105639CRITICALPlane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in PlaneEPSS —CVE-2026-106415—Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a craftedEPSS —CVE-2026-105707MEDIUMuptrace user_handler.go Login information exposureEPSS —CVE-2026-106424—Information leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to readEPSS —CVE-2026-106501CRITICALBackstage: Sensitive information exposure in ScaffolderEPSS —CVE-2026-106459HIGHBackstage: Improper input validation in Sentry scaffolder actionsEPSS —CVE-2026-106334HIGHInformation leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensiEPSS —CVE-2026-63270MEDIUMEnvironment/ini-file leaksEPSS —CVE-2026-86786MEDIUMSlider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_imagesEPSS —CVE-2026-97626—Gitea profile feed disclosure bypassing user visibilityEPSS —