Weaknesses of type CWE-359

214 results

Violação de Privacidade

É a exposição não autorizada de dados sensíveis de um usuário ou sistema, seja por falta de controle de acesso, logging inadequado, ou vazamento em logs/caches. O risco está em dados pessoais, credenciais ou informações confidenciais ficarem acessíveis quando não deveriam.

Example

Uma API que retorna o número de CPF de outros usuários na resposta de um endpoint de perfil público, ou um servidor que grava senhas em claro nos logs de aplicação, permitindo que administradores vejam credenciais de terceiros.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), nunca registre dados sensíveis em logs, aplique mascaramento de dados em APIs (ex: retornar apenas últimos 4 dígitos), e revise regularmente quem tem acesso a quê. Use ferramentas de DLP (Data Loss Prevention) para detectar vazamentos.

CVE-2025-53625HIGHDynamicPageList3 exposes hidden/suppressed usernamesEPSS 0.4%CVE-2026-74966HIGHInformation disclosure in the Form Autofill componentEPSS 0.4%CVE-2024-47085HIGHParameter Manipulation VulnerabilityEPSS 0.4%CVE-2024-45787HIGHInformation Disclosure VulnerabilityEPSS 0.4%CVE-2024-47087HIGHInformation Disclosure VulnerabilityEPSS 0.4%CVE-2025-54124HIGHXWiki Platform: Any user with editing rights can access password properties through Database List PropertiesEPSS 0.4%CVE-2024-42494HIGHRuijie Reyee OS Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.4%CVE-2026-57960HIGHHi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_idEPSS 0.4%CVE-2025-65857HIGHAn issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSEPSS 0.4%CVE-2026-86904HIGHA privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOSEPSS 0.4%CVE-2024-42347HIGHURL preview setting for a room is controllable by the homeserver in matrix-react-sdkEPSS 0.4%CVE-2024-37136MEDIUMDell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Actor vulnerability. AEPSS 0.4%CVE-2025-31276MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Remote content mEPSS 0.4%CVE-2024-6053MEDIUMImproper access control in the clipboard synchronization featureEPSS 0.4%CVE-2025-59843MEDIUMFlagForgeCTF Exposes User Emails via Public /api/user/[username] APIEPSS 0.4%CVE-2024-12041MEDIUMDirectorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated User Information ExposureEPSS 0.4%CVE-2026-84606HIGHA privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visiEPSS 0.4%CVE-2026-48615MEDIUMA flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentialsEPSS 0.4%CVE-2026-50657MEDIUMMicrosoft Defender for Endpoint for Mac Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-20060HIGHDario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.4%