Weaknesses of type CWE-347

644 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2024-11957CRITICALArbitrary Code Execution in WPS OfficeEPSS 0.1%CVE-2026-14837HIGHSSH Enablement Signature Verification BypassEPSS 0.1%CVE-2023-23435MEDIUM Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwritEPSS 0.1%CVE-2023-36811MEDIUMArchive spoofing vulnerability in borgbackupEPSS 0.1%CVE-2026-14296HIGHnRF54H20: MCUBoot can be tricked to executing unauthenticated codeEPSS 0.1%CVE-2025-20143MEDIUMCisco IOS XR Software Secure Boot Bypass VulnerabilityEPSS 0.1%CVE-2026-91814MEDIUMSecurity vulnerability: Foxit PDF Editor/Reader Fails to Detect Modifications to Signed Documents Displaying Newly Added ContentEPSS 0.1%CVE-2024-1721MEDIUMImproper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue aEPSS 0.1%CVE-2026-87732MEDIUMAn issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticateEPSS 0.1%CVE-2024-51526HIGHPermission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentialEPSS 0.1%CVE-2024-2451MEDIUMImproper fingerprint validation in the TeamViewer ClientEPSS 0.1%CVE-2025-27813HIGHMSI Center before 2.0.52.0 has Missing PE Signature Validation.EPSS 0.1%CVE-2025-58356HIGHConstellation allows insecure use of LUKS2 persistent storage partitionsEPSS 0.1%CVE-2025-34324HIGHGoSign Desktop < 2.4.1 Insecure Update Mechanism RCEEPSS 0.1%CVE-2024-36347MEDIUMImproper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicEPSS 0.1%CVE-2023-20236MEDIUMA vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified sofEPSS 0.1%CVE-2024-27244MEDIUMZoom Workplace VDI App for Windows - Insufficient Verification of Data AuthenticityEPSS 0.1%CVE-2026-28199MEDIUMSensitive File Disclosure via Relative Path Traversal in NetBackup Flex OS ShellEPSS 0.1%CVE-2025-64740HIGHZoom Workplace VDI Client for Windows - Improper Verification of Cryptographic SignatureEPSS 0.1%CVE-2026-32294HIGHJetKVM insufficient firmware verificationEPSS 0.1%