Weaknesses of type CWE-347

642 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2026-77105HIGHCommServe Privilege EscalationEPSS 0.2%CVE-2026-22866LOWENS DNSSEC Oracle Vulnerable to RSA Signature Forgery via Missing PKCS#1 v1.5 Padding ValidationEPSS 0.2%CVE-2025-20206HIGHCisco Secure Client for Windows with VPN Posture (HostScan) Module DLL Hijacking VulnerabilityEPSS 0.2%CVE-2026-80465HIGHA vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All vEPSS 0.2%CVE-2022-28756HIGHLocal Privilege Escalation in Auto Updater for Zoom Client for Meetings for macOSEPSS 0.2%CVE-2026-18089HIGHNet::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configuredEPSS 0.2%CVE-2026-39413MEDIUMLightRAG has a JWT Algorithm Confusion Vulnerability in LightRAG APIEPSS 0.2%CVE-2026-46713CRITICALMisskey: JSON-LD signature validation + compaction may lead to improper activity handlingEPSS 0.2%CVE-2025-59803MEDIUMFoxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDEPSS 0.2%CVE-2026-91814MEDIUMSecurity vulnerability: Foxit PDF Editor/Reader Fails to Detect Modifications to Signed Documents Displaying Newly Added ContentEPSS 0.2%CVE-2026-42462HIGHFedify has an LD-Signature Bypass via JSON-LD Named-Graph RestructuringEPSS 0.2%CVE-2021-36277HIGHDell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature VuEPSS 0.2%CVE-2025-36418HIGHMultiple vulnerabilities found in IBM ApplinX.EPSS 0.2%CVE-2025-52556CRITICALrfc3161-client has insufficient verification for timestamp response signaturesEPSS 0.2%CVE-2026-9487CRITICALXML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate IDEPSS 0.2%CVE-2026-47192LOWkas's late signature validation may allow unnoticed repository manipulationsEPSS 0.2%CVE-2025-40934CRITICALXML-Sig prior to 0.68 for Perl improperly validates XML without signaturesEPSS 0.2%CVE-2026-59643HIGHOpenPGP inline-signature policy failures silently ignoredEPSS 0.2%CVE-2026-59639HIGHCMS verifySignatures returns true for SignedData with zero signersEPSS 0.2%CVE-2026-86038HIGHlibp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer IDEPSS 0.2%