Weaknesses of type CWE-88

311 results

Divulgação de Informações

Ocorre quando um programa expõe dados sensíveis (credenciais, tokens, caminhos internos, versões de sistemas) a usuários ou processos não autorizados. O risco está na falta de controle sobre quem acessa o quê, permitindo que informações confidenciais sejam lidas ou inferidas por atacantes.

Example

Um servidor web retorna mensagens de erro detalhadas que revelam a estrutura do banco de dados, ou uma API expõe UUIDs internos de usuários em respostas públicas, ou logs de aplicação contêm senhas armazenadas de forma legível em arquivos acessíveis.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para produção (sem detalhes técnicos), criptografe dados em repouso e em trânsito, revise permissões de arquivos e endpoints, e monitore o que é expostos em respostas HTTP e logs.

CVE-2021-1485MEDIUMCisco IOS XR Software Command Injection VulnerabilityEPSS 0.3%CVE-2026-35033CRITICALJellyfin: Potential SSRF + Arbitrary file read via stream argument injectionEPSS 0.3%CVE-2026-50014MEDIUMpnpm: Git Fetch Argument Injection via Lockfile resolution.commitEPSS 0.3%CVE-2026-4438MEDIUMgethostbyaddr and gethostbyaddr_r return invalid DNS hostnamesEPSS 0.3%CVE-2026-71377CRITICALCommand Argument Injection Vulnerability in Cosminexus Component ContainerEPSS 0.3%CVE-2024-3367MEDIUMArgument injection to runmqscEPSS 0.3%CVE-2026-4519HIGHwebbrowser.open() allows leading dashes in URLsEPSS 0.3%CVE-2026-76212MEDIUMphpMyFAQ before 4.1.7 LIKE Wildcard Injection via PostgreSQLEPSS 0.3%CVE-2025-53509HIGHAdvantech iView Argument InjectionEPSS 0.3%CVE-2026-76219HIGHGitPython before 3.1.58 Arbitrary File Overwrite via read-treeEPSS 0.3%CVE-2026-3515HIGHArgument Injection in prefecthq/prefectEPSS 0.3%CVE-2026-34769HIGHElectron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferenceEPSS 0.3%CVE-2026-4786HIGHIncomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()EPSS 0.3%CVE-2025-52459HIGHAdvantech iView Argument InjectionEPSS 0.3%CVE-2026-62867CRITICALIncus has an argument injection in storage volume block.create_options that leads to arbitrary command executionEPSS 0.3%CVE-2026-85626HIGHgit-mcp-server 2.15.1 Argument Injection via Git Ref ParametersEPSS 0.3%CVE-2023-0633HIGHIn Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in LPEEPSS 0.3%CVE-2026-29954HIGHIn KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of EPSS 0.3%CVE-2026-47250MEDIUMmcp-server-kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltrationEPSS 0.3%CVE-2024-51532HIGHDell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privilegEPSS 0.3%