Weaknesses of type CWE-668

236 results

Divulgação de informações

O software expõe dados sensíveis (credenciais, tokens, dados pessoais, configs internas) a uma entidade não autorizada — seja por acesso direto, mensagens de erro verbosas, logs mal protegidos ou canais inseguros. É a falha de um controle de acesso ou encriptação que deveria manter esses dados privados.

Example

Uma API REST que retorna a senha do usuário em plain text na resposta de login; ou um servidor que deixa arquivos de backup (.sql, .env) acessíveis via web; ou um log de erro que exibe URLs internas e tokens de autenticação em páginas públicas.

How to mitigate

Classifique dados por sensibilidade, nunca exponha em respostas de erro ou logs públicos. Use encriptação em trânsito (TLS) e em repouso, aplique controle de acesso rigoroso aos arquivos sensíveis, e revise regularmente o que seu código imprime em mensagens e registros.

CVE-2023-25954MEDIUMKYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile Print' v3.2.0.230119 EPSS 0.3%CVE-2026-26057MEDIUMSkill Scanner Unsecured Network Binding VulnerabilityEPSS 0.3%CVE-2026-92940CRITICALvm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgentEPSS 0.3%CVE-2026-79031LOWImproper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a craftEPSS 0.3%CVE-2026-61590HIGHdjust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUGEPSS 0.3%CVE-2026-34780HIGHElectron: Context Isolation bypass via contextBridge VideoFrame transferEPSS 0.3%CVE-2025-8107MEDIUMIn OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executiEPSS 0.3%CVE-2024-29905HIGHDIRAC: Unauthorized users can read proxy contents during generationEPSS 0.3%CVE-2025-32783MEDIUMXWiki allows unregistered users to see "public" messages from a closed wiki via notifications from a different wikiEPSS 0.3%CVE-2026-46723MEDIUMInformation Disclosure in extension "Faceted Search" (ke_search)EPSS 0.3%CVE-2020-12020Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13 and ExactaMix EM1200 Versions 1.1, 1.2, and 1.4 does not restrict non administrative EPSS 0.3%CVE-2026-57231HIGHPodman: Malformed Image can trick podman run into leaking host environment variables into the containerEPSS 0.3%CVE-2023-49342MEDIUMTemporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated. The dataEPSS 0.3%CVE-2019-3682HIGHInsecure API port exposed to all Master Node guest containersEPSS 0.3%CVE-2026-47141MEDIUMvm2: NodeVM observability builtins leak host process and HTTP request dataEPSS 0.3%CVE-2026-41369HIGHOpenClaw < 2026.3.31 - Insufficient Environment Variable Sanitization in Host ExecutionEPSS 0.3%CVE-2026-44552HIGHOpen WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache PoisoningEPSS 0.3%CVE-2023-49343MEDIUMTemporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manipulated. The data is EPSS 0.3%CVE-2023-49344MEDIUMTemporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated. TheEPSS 0.3%CVE-2023-49346MEDIUMTemporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated. The datEPSS 0.3%