Weaknesses of type CWE-359

214 results

Violação de Privacidade

É a exposição não autorizada de dados sensíveis de um usuário ou sistema, seja por falta de controle de acesso, logging inadequado, ou vazamento em logs/caches. O risco está em dados pessoais, credenciais ou informações confidenciais ficarem acessíveis quando não deveriam.

Example

Uma API que retorna o número de CPF de outros usuários na resposta de um endpoint de perfil público, ou um servidor que grava senhas em claro nos logs de aplicação, permitindo que administradores vejam credenciais de terceiros.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), nunca registre dados sensíveis em logs, aplique mascaramento de dados em APIs (ex: retornar apenas últimos 4 dígitos), e revise regularmente quem tem acesso a quê. Use ferramentas de DLP (Data Loss Prevention) para detectar vazamentos.

CVE-2023-22918MEDIUMA post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEEPSS 0.8%CVE-2026-20834MEDIUMWindows Spoofing VulnerabilityEPSS 0.8%CVE-2023-35151HIGHXWiki Platform may show email addresses in clear in REST resultsEPSS 0.7%CVE-2023-29203LOWUnauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm EPSS 0.7%CVE-2026-56171HIGHWindows Remote Desktop Protocol (RDP) Information Disclosure VulnerabilityEPSS 0.7%CVE-2025-66035HIGHAngular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLsEPSS 0.7%CVE-2019-25762HIGHJoomla! Component JoomProject 1.1.3.2 Information DisclosureEPSS 0.7%CVE-2026-48048HIGHXWiki Platform's Livetable results still allow reconstructing password hashes using 768 requestsEPSS 0.7%CVE-2024-27850MEDIUMThis issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, mEPSS 0.7%CVE-2023-7014MEDIUMAuthor Box, Guest Author and Co-Authors for Your Posts – Molongui <= 4.7.4 - Information Exposure via ma_debugEPSS 0.7%CVE-2026-56124HIGHphpUploader < 2.0.2 Unauthenticated Database Exposure via index modelEPSS 0.6%CVE-2026-24735HIGHApache Answer: Revision API Improper Access Control leads to Information DisclosureEPSS 0.6%CVE-2023-5983HIGHInformation Disclosure in Botanik Software Pharmacy AutomationEPSS 0.6%CVE-2026-62328HIGH9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage EndpointsEPSS 0.6%CVE-2024-7697HIGHLogical vulnerability in com.transsion.carlcareEPSS 0.6%CVE-2024-10267HIGHInformation Disclosure in transformeroptimus/superagiEPSS 0.6%CVE-2026-34226HIGHHappy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookiesEPSS 0.6%CVE-2020-37173HIGHAVideo Platform 8.1 - Information Disclosure (User Enumeration)EPSS 0.6%CVE-2023-1936LOWExposure of Private Personal Information to an Unauthorized Actor in GitLabEPSS 0.6%CVE-2026-25699MEDIUMApache Answer: Authorization Bypass in Timeline APIEPSS 0.6%