Weaknesses of type CWE-88

311 results

Divulgação de Informações

Ocorre quando um programa expõe dados sensíveis (credenciais, tokens, caminhos internos, versões de sistemas) a usuários ou processos não autorizados. O risco está na falta de controle sobre quem acessa o quê, permitindo que informações confidenciais sejam lidas ou inferidas por atacantes.

Example

Um servidor web retorna mensagens de erro detalhadas que revelam a estrutura do banco de dados, ou uma API expõe UUIDs internos de usuários em respostas públicas, ou logs de aplicação contêm senhas armazenadas de forma legível em arquivos acessíveis.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para produção (sem detalhes técnicos), criptografe dados em repouso e em trânsito, revise permissões de arquivos e endpoints, e monitore o que é expostos em respostas HTTP e logs.

CVE-2025-6232HIGHAn improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute coEPSS 0.2%CVE-2025-67858HIGHA crafted "interface" input parameter can lead to integrity loss of the firewall configurationEPSS 0.2%CVE-2026-11968MEDIUMImproper Neutralization of Argument Delimiters in a Command ('Argument Injection') in TortoiseGitEPSS 0.2%CVE-2026-64624HIGHFreeRDP RDP File Parser Remote Code Execution via CLI OptionsEPSS 0.2%CVE-2026-16493HIGHAnsible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for cve-2026-11332)EPSS 0.2%CVE-2026-81529HIGHConnection-option injection via unescaped settings in the canonical MongoDB URL builderEPSS 0.2%CVE-2026-68939LOWPyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)EPSS 0.2%CVE-2026-43943HIGHelecterm: RCE via malicious SSH server filename in openFileWithEditorEPSS 0.2%CVE-2026-68766HIGHhashcat through 7.1.2 Arbitrary File Write via Restore File Option InjectionEPSS 0.2%CVE-2025-41761HIGHPrivilege escalation possibleEPSS 0.2%CVE-2026-94588MEDIUMIn Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper EPSS 0.2%CVE-2026-45181MEDIUMHex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers EPSS 0.2%CVE-2026-89066HIGHOS command injection in the task synthesis component in projenEPSS 0.2%CVE-2026-78635MEDIUMImproper Input Validation in the Okta Privileged Access SSH Client URL Handler ArgumentEPSS 0.2%CVE-2026-44712HIGHpam_usb: Shell injection via device UUID and username in pamusb-conf and pamusb-agentEPSS 0.2%CVE-2025-66002MEDIUMLocal users can perform arbitrary unmounts via smb4k mount helper due to lack of input validationEPSS 0.2%CVE-2026-80427HIGHbestzip before 2.2.6 and 3.0.x before 3.0.2 Argument Injection via Missing Option DelimiterEPSS 0.2%CVE-2026-93337HIGHNetworkManager-l2tp Privilege Escalation via pppd Plugin InjectionEPSS 0.1%CVE-2026-90894HIGHParallels Desktop local privilege escalation via appliance extract argument injectionEPSS 0.1%CVE-2026-1716MEDIUMAn input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow aEPSS 0.1%