Weaknesses of type CWE-359

214 results

Violação de Privacidade

É a exposição não autorizada de dados sensíveis de um usuário ou sistema, seja por falta de controle de acesso, logging inadequado, ou vazamento em logs/caches. O risco está em dados pessoais, credenciais ou informações confidenciais ficarem acessíveis quando não deveriam.

Example

Uma API que retorna o número de CPF de outros usuários na resposta de um endpoint de perfil público, ou um servidor que grava senhas em claro nos logs de aplicação, permitindo que administradores vejam credenciais de terceiros.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), nunca registre dados sensíveis em logs, aplique mascaramento de dados em APIs (ex: retornar apenas últimos 4 dígitos), e revise regularmente quem tem acesso a quê. Use ferramentas de DLP (Data Loss Prevention) para detectar vazamentos.

CVE-2025-5334HIGHExposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows EPSS 0.6%CVE-2023-2703HIGHInformation Disclosure in Finex Media's Competition Management SystemEPSS 0.6%CVE-2023-44255LOWAn exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 anEPSS 0.6%CVE-2025-43405HIGHA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, maEPSS 0.6%CVE-2025-43399HIGHThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS SequoiEPSS 0.6%CVE-2024-46979MEDIUMData leak of notification filters of users in XWiki PlatformEPSS 0.5%CVE-2026-58297HIGHMicrosoft Edge for Android Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-58296HIGHMicrosoft Edge for Android Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-29888MEDIUMSaleor vulnerable to customers addresses leak when using Warehouse as a `Pickup: Local stock only` delivery methodEPSS 0.5%CVE-2021-36723MEDIUMEmuse - eServices / eNvoice Exposure Of Private Personal InformationEPSS 0.5%CVE-2025-66171MEDIUMApache CloudStack: Any user can create a new VM from backups they should not have access toEPSS 0.5%CVE-2023-50053HIGHAn issue in Foundation.app Foundation platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication procEPSS 0.5%CVE-2022-46168LOWGroup SMTP user emails are exposed in CC email headerEPSS 0.5%CVE-2024-13215MEDIUMElementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure via Modal PopupEPSS 0.5%CVE-2023-6695MEDIUMBeaver Themer <= 1.4.9 - Authenticated (Contributor+) Sensitive Information Exposure via shortcodeEPSS 0.5%CVE-2024-29986MEDIUMMicrosoft Edge for Android (Chromium-based) Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-30321HIGHA vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versioEPSS 0.5%CVE-2025-66172HIGHApache CloudStack: Any user can attach a volume in their VMs from backups they should not have access toEPSS 0.5%CVE-2023-2239HIGHExposure of Private Personal Information to an Unauthorized Actor in microweber/microweberEPSS 0.5%CVE-2026-28906HIGHThis issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, mEPSS 0.5%