Weaknesses of type CWE-88

311 results

Divulgação de Informações

Ocorre quando um programa expõe dados sensíveis (credenciais, tokens, caminhos internos, versões de sistemas) a usuários ou processos não autorizados. O risco está na falta de controle sobre quem acessa o quê, permitindo que informações confidenciais sejam lidas ou inferidas por atacantes.

Example

Um servidor web retorna mensagens de erro detalhadas que revelam a estrutura do banco de dados, ou uma API expõe UUIDs internos de usuários em respostas públicas, ou logs de aplicação contêm senhas armazenadas de forma legível em arquivos acessíveis.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para produção (sem detalhes técnicos), criptografe dados em repouso e em trânsito, revise permissões de arquivos e endpoints, e monitore o que é expostos em respostas HTTP e logs.

CVE-2026-44450CRITICALLumiverse: RCE via MCP stdio argument injectionEPSS 0.4%CVE-2026-17347HIGHpgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitutionEPSS 0.4%CVE-2026-53783HIGHrsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsyncEPSS 0.4%CVE-2026-86864HIGHpgAdmin 4: Argument and connection-string injection via the database field in the Backup toolEPSS 0.4%CVE-2026-28197CRITICALPrivilege Escalation via Argument Injection in NetBackup Flex OS ShellEPSS 0.4%CVE-2025-47421HIGHPrivilege escalation via SCP loginEPSS 0.4%CVE-2026-48116HIGHAnythingLLM: RCE via ripgrep --pre argument injection in filesystem-search-files agent skillEPSS 0.4%CVE-2025-12613HIGHVersions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing of parameter values cEPSS 0.4%CVE-2026-63046HIGHApache InLong: Agent Installer — Command Injection to RCE via Default CredentialsEPSS 0.4%CVE-2026-12530HIGHImproper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()EPSS 0.3%CVE-2025-23073LOWAPI list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets parameterEPSS 0.3%CVE-2026-35538LOWAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injectioEPSS 0.3%CVE-2026-50147HIGHMetabase: Arbitrary File Read via MySQL Connection Property InjectionEPSS 0.3%CVE-2026-73624HIGHGitPython before 3.1.54 Arbitrary File Overwrite via diffEPSS 0.3%CVE-2026-20016MEDIUMA vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authentEPSS 0.3%CVE-2025-43905MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 releasEPSS 0.3%CVE-2026-2449CRITICALImproper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions upKeeper Instant PrivEPSS 0.3%CVE-2026-90809MEDIUMHKUDS nanobot ExecTool shell.py ExecTool._spawn argument injectionEPSS 0.3%CVE-2026-78637MEDIUMFdawgs node-poppler Argument Injection index.js pdfUnite argument injectionEPSS 0.3%CVE-2020-27129MEDIUMCisco SD-WAN vManage Software Command Injection VulnerabilityEPSS 0.3%