Weaknesses of type CWE-359

214 results

Violação de Privacidade

É a exposição não autorizada de dados sensíveis de um usuário ou sistema, seja por falta de controle de acesso, logging inadequado, ou vazamento em logs/caches. O risco está em dados pessoais, credenciais ou informações confidenciais ficarem acessíveis quando não deveriam.

Example

Uma API que retorna o número de CPF de outros usuários na resposta de um endpoint de perfil público, ou um servidor que grava senhas em claro nos logs de aplicação, permitindo que administradores vejam credenciais de terceiros.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), nunca registre dados sensíveis em logs, aplique mascaramento de dados em APIs (ex: retornar apenas últimos 4 dígitos), e revise regularmente quem tem acesso a quê. Use ferramentas de DLP (Data Loss Prevention) para detectar vazamentos.

CVE-2026-41182MEDIUMLangSmith SDK: Streaming token events bypass output redactionEPSS 0.4%CVE-2026-6765MEDIUMInformation disclosure in the Form Autofill componentEPSS 0.4%CVE-2025-68945MEDIUMIn Gitea before 1.21.2, an anonymous user can visit a private user's project.EPSS 0.4%CVE-2025-66027HIGHRallly Information Disclosure Vulnerability in Participant API Leaks Names and Emails Despite Pro Privacy SettingsEPSS 0.4%CVE-2024-13953MEDIUMSensitive Information disclosed in log filesEPSS 0.4%CVE-2023-6630MEDIUMContact Form 7 – Dynamic Text Extension <= 4.1.0 - Insecure Direct Object ReferenceEPSS 0.3%CVE-2025-11145HIGHUser Enumeration in CBK Soft's enVisionEPSS 0.3%CVE-2025-26816MEDIUMA vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users with particular perEPSS 0.3%CVE-2025-25042MEDIUMAuthenticated Access Control Vulnerability allows Sensitive Information Disclosure in AOS-CX REST InterfaceEPSS 0.3%CVE-2026-58510MEDIUMGHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->privateEPSS 0.3%CVE-2025-0679MEDIUMExposure of Private Personal Information to an Unauthorized Actor in GitLabEPSS 0.3%CVE-2025-62362MEDIUMName and e-mail of employee that has done a publication is discoverable in gpp-burgerportaalEPSS 0.3%CVE-2025-49134LOWWeblate exposes personal IP address via e-mailEPSS 0.3%CVE-2020-1688MEDIUMJunos OS: SRX and NFX Series: Insufficient Web API private key protectionEPSS 0.3%CVE-2024-13216MEDIUMHT Event – WordPress Event Manager Plugin for Elementor <= 1.4.7 - Authenticated (Contributor+) Sensitive Information Exposure via HT Event: SponsorEPSS 0.3%CVE-2024-8891MEDIUMExposure of Private Personal Information to an Unauthorized Actor vulnerability on CIRCUTOR Q-SMTEPSS 0.3%CVE-2023-45720MEDIUMHCL Leap is affected by a disclosure of private personal information vulnerabilityEPSS 0.3%CVE-2026-88875MEDIUMAVideo Incomplete API Sanitization Information DisclosureEPSS 0.3%CVE-2025-1030HIGHSensitive Data Exposure in Utarit Informatics' SoliClubEPSS 0.3%CVE-2024-11216HIGHBroken Access Control in PozitifIK's Pik OnlineEPSS 0.3%