Weaknesses of type CWE-359

214 results

Violação de Privacidade

É a exposição não autorizada de dados sensíveis de um usuário ou sistema, seja por falta de controle de acesso, logging inadequado, ou vazamento em logs/caches. O risco está em dados pessoais, credenciais ou informações confidenciais ficarem acessíveis quando não deveriam.

Example

Uma API que retorna o número de CPF de outros usuários na resposta de um endpoint de perfil público, ou um servidor que grava senhas em claro nos logs de aplicação, permitindo que administradores vejam credenciais de terceiros.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), nunca registre dados sensíveis em logs, aplique mascaramento de dados em APIs (ex: retornar apenas últimos 4 dígitos), e revise regularmente quem tem acesso a quê. Use ferramentas de DLP (Data Loss Prevention) para detectar vazamentos.

CVE-2024-29987MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 1.2%CVE-2022-1365HIGHExposure of Private Personal Information to an Unauthorized Actor in lquixada/cross-fetchEPSS 1.2%CVE-2022-24820MEDIUMUnauthenticated user can list hidden document from multiple velocity templatesEPSS 1.0%CVE-2022-20942MEDIUMA vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and CiscoEPSS 0.9%CVE-2022-24890LOWExposure of Private Personal Information to an Unauthorized Actor in Nextcloud TalkEPSS 0.9%CVE-2024-40796MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macEPSS 0.9%CVE-2021-21823MEDIUMAn information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 11.1.11. A specially EPSS 0.9%CVE-2023-44156MEDIUMSensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) beforeEPSS 0.9%CVE-2025-34441MEDIUMAVideo < 20.1 User Information Disclosure via Public APIEPSS 0.9%CVE-2021-46687MEDIUMJFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. EPSS 0.8%CVE-2022-24719LOWUnauthorized forwarding of confidential headers in fluture-nodeEPSS 0.8%CVE-2024-27881MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Monterey 12.7.6, macOS SonoEPSS 0.8%CVE-2025-49715HIGHDynamics 365 FastTrack Implementation Assets Information Disclosure VulnerabilityEPSS 0.8%CVE-2025-51586LOWAn issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive inEPSS 0.8%CVE-2022-36091HIGHXWiki Platform Web Templates vulnerable to Missing Authorization and Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.8%CVE-2023-26041LOWNextcloud Talk messages can still be seen on conversation after expiring when cron is misconfiguredEPSS 0.8%CVE-2022-41971MEDIUMNextcloud Talk guests can continue to receive video streams from call after being removed from a conversationEPSS 0.8%CVE-2025-0683HIGHExposure of Private Personal Information to an Unauthorized Actor vulnerability in Contec Health CMS8000 Patient MonitorEPSS 0.8%CVE-2025-12536MEDIUMSureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information ExposureEPSS 0.8%CVE-2022-41936MEDIUMExposure of Private Personal Information to an Unauthorized Actor in xwiki-platform-rest-serverEPSS 0.8%