Weaknesses of type CWE-347

644 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2024-53267MEDIUMVulnerability with bundle verification in sigstore-javaEPSS 0.1%CVE-2025-20248MEDIUMCisco IOS XR Software Image Verification Bypass VulnerabilityEPSS 0.1%CVE-2026-75946HIGHOMEN Gaming Hub – Potential Escalation of Privilege & Information DisclosureEPSS 0.1%CVE-2026-45614MEDIUMOP-TEE vulnerable to ECDH private key recoveryEPSS 0.1%CVE-2023-20135MEDIUMA vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code onEPSS 0.1%CVE-2026-52486MEDIUMAn issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument moduleEPSS 0.1%CVE-2024-23581MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerabilityEPSS 0.1%CVE-2026-0392HIGHeParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-updateEPSS 0.1%CVE-2025-64456HIGHIn JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalationEPSS 0.1%CVE-2025-30064HIGHPossibility to generate a session for any user via the "ex:action" parameter after obtaining access to the JWT keyEPSS 0.1%CVE-2026-4541LOWjanmojzis tinyssh Ed25519 Signature crypto_sign_ed25519_tinyssh.c signature verificationEPSS 0.1%CVE-2025-54549MEDIUMCryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISOEPSS 0.1%CVE-2024-36334HIGHImproper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the installation directory toEPSS 0.1%CVE-2025-46774MEDIUMAn Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version EPSS 0.1%CVE-2026-17872MEDIUMCryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a saEPSS 0.1%CVE-2026-48791LOWSigstore Java has a vulnerability with bundle verification of integratedTimeEPSS 0.1%CVE-2025-23364MEDIUMA vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signingEPSS 0.1%CVE-2023-20940HIGHIn the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This could lead to localEPSS 0.1%CVE-2026-16742MEDIUMsystemd-homed: local privilege escalation via missing home-record signature verification on the authenticate pathEPSS 0.1%CVE-2026-28590HIGHIn multiple locations, there is a possible improper encryption key validation due to a logic error in the code. This could lead to local escEPSS 0.1%