Weaknesses of type CWE-347

642 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2025-68925MEDIUMJervis has a JWT Algorithm Confusion VulnerabilityEPSS 0.1%CVE-2025-59324CRITICALCPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPEPSS 0.1%CVE-2024-8036MEDIUMUnauthorized Modifications of Firmware and ConfigurationEPSS 0.1%CVE-2026-28432HIGHHTTP signature verification can be bypassedEPSS 0.1%CVE-2022-28752HIGHLocal Privilege Escalation in the Zoom Rooms for Windows ClientEPSS 0.1%CVE-2026-41694LOWSAML Payloads Decrypted Without Valid SignatureEPSS 0.1%CVE-2026-1568CRITICALRapid7 InsightVM Signature Validation VulnerabilityEPSS 0.1%CVE-2026-5466HIGHwc_VerifyEccsiHash missing sanity checkEPSS 0.1%CVE-2026-55961HIGHwolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signerEPSS 0.1%CVE-2023-43611HIGHBIG-IP Edge Client for macOS vulnerabilityEPSS 0.1%CVE-2024-54126HIGHInsufficient Integrity Verification Vulnerability in TP-Link Archer C50EPSS 0.1%CVE-2026-81680CRITICALopenssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot RemovalEPSS 0.1%CVE-2026-82955CRITICALIn the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API GaEPSS 0.1%CVE-2023-38418HIGHBIG-IP Edge Client for macOS vulnerabilityEPSS 0.1%CVE-2026-7689MEDIUMDolibarr ERP CRM Online Signature security.lib.php dol_verifyHash signature verificationEPSS 0.1%CVE-2026-79389HIGHTrueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modifEPSS 0.1%CVE-2026-42743MEDIUMWordPress Masteriyo - LMS plugin <= 2.1.8 - Broken Authentication vulnerabilityEPSS 0.1%CVE-2026-94368HIGHNoobaa-core: noobaa-core: presigned put url escalation to copyobject via unsigned x-amz-copy-source headerEPSS 0.1%CVE-2026-12860HIGHRSA PKCS#1 verification skips last two hash bytes in NULL-omitted pathEPSS 0.1%CVE-2026-34155HIGHRAUC: Improper Signing of Plain Bundles Exceeding 2 GiBEPSS 0.1%