Weaknesses of type CWE-668

235 results

Divulgação de informações

O software expõe dados sensíveis (credenciais, tokens, dados pessoais, configs internas) a uma entidade não autorizada — seja por acesso direto, mensagens de erro verbosas, logs mal protegidos ou canais inseguros. É a falha de um controle de acesso ou encriptação que deveria manter esses dados privados.

Example

Uma API REST que retorna a senha do usuário em plain text na resposta de login; ou um servidor que deixa arquivos de backup (.sql, .env) acessíveis via web; ou um log de erro que exibe URLs internas e tokens de autenticação em páginas públicas.

How to mitigate

Classifique dados por sensibilidade, nunca exponha em respostas de erro ou logs públicos. Use encriptação em trânsito (TLS) e em repouso, aplique controle de acesso rigoroso aos arquivos sensíveis, e revise regularmente o que seu código imprime em mensagens e registros.

CVE-2024-3019HIGHPcp: exposure of the redis server backend allows remote command execution via pmproxyEPSS 1.0%CVE-2022-29247LOWExposure of Resource to Wrong Sphere in ElectronEPSS 1.0%CVE-2022-0815MEDIUMMcAfee WebAdvisor - Extension Fingerprinting vulnerabilityEPSS 1.0%CVE-2023-34114HIGHExposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potenEPSS 1.0%CVE-2023-28433HIGHMinio Privilege Escalation on Windows via Path separator manipulationEPSS 1.0%CVE-2022-1467HIGHAVEVA InTouch Access Anywhere Exposure of Resource to Wrong SphereEPSS 1.0%CVE-2021-40496SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attackEPSS 0.9%CVE-2021-20999CRITICALWEIDMUELLER: Accidentally open network port in u-controls and IoT-GatewaysEPSS 0.9%CVE-2022-21718LOWRenderers can obtain access to random bluetooth device without permission in ElectronEPSS 0.9%CVE-2023-35696HIGHUnauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the deEPSS 0.9%CVE-2021-41140MEDIUMReactions leak for secure category topics and private messagesEPSS 0.9%CVE-2023-29208HIGHData leak through deleted documents EPSS 0.9%CVE-2025-32428CRITICALJupyter Remote Desktop Proxy makes TigerVNC accessible via the network and not just via a UNIX socket as intendedEPSS 0.9%CVE-2026-20160CRITICALCisco Smart Software Manager On-Prem Arbitrary Command Execution VulnerabilityEPSS 0.9%CVE-2022-32249Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gaEPSS 0.9%CVE-2020-26084MEDIUMCisco Edge Fog Fabric Resource Exposure VulnerabilityEPSS 0.9%CVE-2021-32788MEDIUMPost creator of a whisper post can be revealed to non-staff users in DiscourseEPSS 0.9%CVE-2022-20917MEDIUMA vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticEPSS 0.9%CVE-2026-44008CRITICALvm2: Snabox breakout via `neutralizeArraySpeciesBatch`EPSS 0.9%CVE-2020-26086MEDIUMCisco TelePresence Collaboration Endpoint Software Information Disclosure VulnerabilityEPSS 0.8%