Weaknesses of type CWE-347

641 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2026-87802CRITICALApache Syncope: SRA OAuth2 JWT signature verification bypassEPSS 0.3%CVE-2026-23518CRITICALFleet has a JWT signature bypass vulnerability in Azure AD MDM enrollmentEPSS 0.3%CVE-2026-34377HIGHZebra has a Consensus Failure due to Improper Verification of V5 TransactionsEPSS 0.3%CVE-2026-62757MEDIUMWindows Schannel Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-7511MEDIUMPKCS7_verify signer confusion allows forged signatures to be acceptedEPSS 0.3%CVE-2026-11348HIGHAuthentication Bypass in HAVELSAN's Open Source Project Liman MYSEPSS 0.3%CVE-2026-6911CRITICALAuthentication Bypass via Missing JWT Signature Verification in AWS Ops WheelEPSS 0.3%CVE-2026-41301MEDIUMOpenClaw 2026.3.22 < 2026.3.31 - Forged Nostr DM Pairing State Creation via Signature Verification BypassEPSS 0.3%CVE-2026-52754HIGHGhidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModuleEPSS 0.3%CVE-2021-3633HIGHA DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalationEPSS 0.3%CVE-2026-59163CRITICALMnemosyne has JWT signature verification bypass sync server that allows authentication bypassEPSS 0.3%CVE-2025-2764HIGHCarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution VulnerabilityEPSS 0.3%CVE-2026-24032MEDIUMA vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weaEPSS 0.3%CVE-2024-10237HIGHSMC BMC Firmware Image Authentication Design IssueEPSS 0.2%CVE-2019-1736MEDIUMMultiple Cisco UCS-Based Products UEFI Secure Boot Bypass VulnerabilityEPSS 0.2%CVE-2023-40012MEDIUMuthenticode EKU validation bypassEPSS 0.2%CVE-2026-48747MEDIUMSymfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm DowngradeEPSS 0.2%CVE-2026-32974HIGHOpenClaw < 2026.3.12 - Forged Event Injection via Feishu Webhook Verification TokenEPSS 0.2%CVE-2019-1615MEDIUMCisco NX-OS Software Image Signature Verification VulnerabilityEPSS 0.2%CVE-2026-4258HIGHVersions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve vEPSS 0.2%