Weaknesses of type CWE-88

311 results

Divulgação de Informações

Ocorre quando um programa expõe dados sensíveis (credenciais, tokens, caminhos internos, versões de sistemas) a usuários ou processos não autorizados. O risco está na falta de controle sobre quem acessa o quê, permitindo que informações confidenciais sejam lidas ou inferidas por atacantes.

Example

Um servidor web retorna mensagens de erro detalhadas que revelam a estrutura do banco de dados, ou uma API expõe UUIDs internos de usuários em respostas públicas, ou logs de aplicação contêm senhas armazenadas de forma legível em arquivos acessíveis.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para produção (sem detalhes técnicos), criptografe dados em repouso e em trânsito, revise permissões de arquivos e endpoints, e monitore o que é expostos em respostas HTTP e logs.

CVE-2026-0304MEDIUMCortex XDR Broker VM: Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-59433MEDIUM@conventional-changelog/git-client has an Argument Injection vulnerabilityEPSS 0.2%CVE-2025-43730HIGHDell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ('Argument InjectionEPSS 0.2%CVE-2026-35153MEDIUMDell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 throughEPSS 0.2%CVE-2026-24739MEDIUMSymfony has incorrect argument escaping under MSYS2/Git Bash on Windows that can lead to destructive file operationsEPSS 0.2%CVE-2026-73621MEDIUMGitPython before 3.1.56 Arbitrary File Truncation via Commit.countEPSS 0.2%CVE-2026-14459HIGHArgument Injection in TUBITAK BILGEM's pardus-softwareEPSS 0.2%CVE-2026-86862HIGHpgAdmin 4: Connection-string injection via the database field in the Restore and Maintenance toolsEPSS 0.2%CVE-2026-43698HIGHAn injection issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 1EPSS 0.2%CVE-2026-44968MEDIUMdbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type ParametersEPSS 0.2%CVE-2025-36565MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 releasEPSS 0.2%CVE-2026-15793MEDIUMGit source checkout from a bundle file could lead to command injectionEPSS 0.2%CVE-2026-48711HIGHSSHFS: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')EPSS 0.2%CVE-2026-55887HIGHMCP Gateway: Argument injection via OCI image label YAML in Docker MCP GatewayEPSS 0.2%CVE-2026-4145HIGHDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticatEPSS 0.2%CVE-2025-24845MEDIUMImproper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.EPSS 0.2%CVE-2026-41570HIGHPHPUnit: Argument injection via newline in PHP INI values forwarded to child processesEPSS 0.2%CVE-2026-20063MEDIUMCisco Secure FTD Software Authenticated Command Injection VulnerabilityEPSS 0.2%CVE-2026-87794HIGHbestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip DestinationEPSS 0.2%CVE-2025-6231HIGHAn improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute coEPSS 0.2%