Weaknesses of type CWE-668

236 results

Divulgação de informações

O software expõe dados sensíveis (credenciais, tokens, dados pessoais, configs internas) a uma entidade não autorizada — seja por acesso direto, mensagens de erro verbosas, logs mal protegidos ou canais inseguros. É a falha de um controle de acesso ou encriptação que deveria manter esses dados privados.

Example

Uma API REST que retorna a senha do usuário em plain text na resposta de login; ou um servidor que deixa arquivos de backup (.sql, .env) acessíveis via web; ou um log de erro que exibe URLs internas e tokens de autenticação em páginas públicas.

How to mitigate

Classifique dados por sensibilidade, nunca exponha em respostas de erro ou logs públicos. Use encriptação em trânsito (TLS) e em repouso, aplique controle de acesso rigoroso aos arquivos sensíveis, e revise regularmente o que seu código imprime em mensagens e registros.

CVE-2022-46756HIGH Dell VxRail, versions prior to 7.0.410, contain a Container Escape Vulnerability. A local high-privileged attacker could potentially exploiEPSS 0.2%CVE-2026-82652MEDIUMSiYuan before v3.8.1 Information Disclosure via Publish AccessEPSS 0.2%CVE-2023-3670HIGHCodesys: Vulnerability in CODESYS Development System and CODESYS ScriptingEPSS 0.2%CVE-2026-34095NONEaction=raw with Special:Mypage subpage title responds with "Content-Type: text/html" on ctype=text/javascript requestEPSS 0.2%CVE-2026-46430MEDIUMAlgernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOSEPSS 0.2%CVE-2026-53657HIGHLima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socketEPSS 0.2%CVE-2024-21813HIGHExposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potentially enable escalatiEPSS 0.2%CVE-2026-53826LOWOpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session SpawnEPSS 0.2%CVE-2023-24523HIGHAn attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7EPSS 0.2%CVE-2021-26343MEDIUMInsufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memoEPSS 0.2%CVE-2022-38087MEDIUMExposure of resource to wrong sphere in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable informaEPSS 0.2%CVE-2026-72924LOWGitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by defaultEPSS 0.2%CVE-2021-41094MEDIUMMandatory encryption at rest can be bypassed (UI) in Wire appEPSS 0.2%CVE-2022-26355Citrix Federated Authentication Service (FAS)EPSS 0.2%CVE-2024-43704HIGHGPU DDK - PowerVR: PVRSRVAcquireProcessHandleBase can cause psProcessHandleBase reuse when PIDs are reusedEPSS 0.2%CVE-2023-5751HIGHCODESYS: Development system prone to DoS through exposure of resource to wrong sphereEPSS 0.2%CVE-2026-86551LOWWi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z80Ultra (NX741J) productEPSS 0.2%CVE-2026-34094LOWCustomized help link for page protection indicator is relative to subpage name, because the link target is missing the "/wiki/" prefixEPSS 0.2%CVE-2025-15653HIGHDräger Zeus IE Anesthesia Workstation USB Interface Privilege EscalationEPSS 0.2%CVE-2024-24985HIGHExposure of resource to wrong sphere in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to potentially enable escalaEPSS 0.2%