Weaknesses of type CWE-88

311 results

Divulgação de Informações

Ocorre quando um programa expõe dados sensíveis (credenciais, tokens, caminhos internos, versões de sistemas) a usuários ou processos não autorizados. O risco está na falta de controle sobre quem acessa o quê, permitindo que informações confidenciais sejam lidas ou inferidas por atacantes.

Example

Um servidor web retorna mensagens de erro detalhadas que revelam a estrutura do banco de dados, ou uma API expõe UUIDs internos de usuários em respostas públicas, ou logs de aplicação contêm senhas armazenadas de forma legível em arquivos acessíveis.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para produção (sem detalhes técnicos), criptografe dados em repouso e em trânsito, revise permissões de arquivos e endpoints, e monitore o que é expostos em respostas HTTP e logs.

CVE-2023-26310HIGHCommand Injection In OPPO ServiceEPSS 1.1%CVE-2024-3684HIGHImproper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management ConsoleEPSS 1.1%CVE-2026-22738CRITICALSpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code ExecutionEPSS 1.1%CVE-2024-23731CRITICALThe OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function arguEPSS 1.1%CVE-2026-86060CRITICALSSH session privilege manipulation via a crafted username in Mikrotik RouterOSEPSS 1.1%KEVCVE-2025-35010HIGHMicrohard Bullet-LTE and IPn4Gii AT+MNPINGTM Argument InjectionEPSS 1.0%CVE-2025-35009HIGHMicrohard Bullet-LTE and IPn4Gii AT+MNNETSP Argument InjectionEPSS 1.0%CVE-2025-35006HIGHMicrohard Bullet-LTE and IPn4Gii AT+MFPORTFWD Argument InjectionEPSS 1.0%CVE-2025-35008HIGHMicrohard Bullet-LTE and IPn4Gii AT+MMNAME Argument InjectionEPSS 1.0%CVE-2025-35005HIGHMicrohard Bullet-LTE and IPn4Gii AT+MFMAC Argument InjectionEPSS 1.0%CVE-2025-35007HIGHMicrohard Bullet-LTE and IPn4Gii AT+MFRULE Argument InjectionEPSS 1.0%CVE-2025-35004HIGHMicrohard Bullet-LTE and IPn4Gii AT+MFIP Argument InjectionEPSS 1.0%CVE-2022-47502Apache OpenOffice: Macro URL arbitrary script executionEPSS 1.0%CVE-2026-57572CRITICALCrawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_argsEPSS 0.9%CVE-2025-3460HIGHON Semiconductor Quantenna set_tx_pow Argument InjectionEPSS 0.9%CVE-2025-48385HIGHGit alllows arbitrary file writes via bundle-uri parameter injectionEPSS 0.9%CVE-2024-35307CRITICALArgument Injection Leading to Remote Code Execution in Realtime Graph ExtensionEPSS 0.9%CVE-2022-1399CRITICALRemote code execution in scheduled tasks componentEPSS 0.9%CVE-2024-47516CRITICALPagure: argument injection in pagurerepo.log()EPSS 0.9%CVE-2026-6951CRITICALVersions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912]EPSS 0.9%