Weaknesses of type CWE-347

642 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2025-12007HIGHSupermicro BMC firmware update validation bypassEPSS 0.1%CVE-2026-1237LOWVulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to upEPSS 0.1%CVE-2025-43521MEDIUMA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2023-40727HIGHA vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak oEPSS 0.1%CVE-2025-43390MEDIUMA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2024-40592MEDIUMAn improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, verEPSS 0.1%CVE-2025-34503HIGHShuffle Master Deck Mate 1 Unauthenticated EEPROM Firmware ExecutionEPSS 0.1%CVE-2026-84185MEDIUMJwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verificationEPSS 0.1%CVE-2025-0824LOWlack of validation for firmware update in Hitachi Virtual StorageEPSS 0.1%CVE-2024-5912MEDIUMCortex XDR Agent: Improper File Signature Verification ChecksEPSS 0.1%CVE-2026-50720MEDIUMThe Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32EPSS 0.1%CVE-2024-47476HIGHDell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthEPSS 0.1%CVE-2024-23460MEDIUMIncorrect signature validation of packageEPSS 0.1%CVE-2026-85995HIGHNotepad++: Authenticode verification bypass allows modified updater executionEPSS 0.1%CVE-2026-18152HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.1%CVE-2024-38807MEDIUMCVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's LoaderEPSS 0.1%CVE-2025-27498MEDIUMAEADs/ascon-aead: Plaintext exposed in decrypt_in_place_detached even on tag verification failureEPSS 0.1%CVE-2026-73776HIGHAuthenticated Signature Verification Bypass Leading to Arbitrary Code Execution in AOS-CXEPSS 0.1%CVE-2022-4418HIGHLocal privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect HomEPSS 0.1%CVE-2026-59112MEDIUMSignature validation vulnerability affecting DigiDoc applicationsEPSS 0.1%