Weaknesses of type CWE-88

311 results

Divulgação de Informações

Ocorre quando um programa expõe dados sensíveis (credenciais, tokens, caminhos internos, versões de sistemas) a usuários ou processos não autorizados. O risco está na falta de controle sobre quem acessa o quê, permitindo que informações confidenciais sejam lidas ou inferidas por atacantes.

Example

Um servidor web retorna mensagens de erro detalhadas que revelam a estrutura do banco de dados, ou uma API expõe UUIDs internos de usuários em respostas públicas, ou logs de aplicação contêm senhas armazenadas de forma legível em arquivos acessíveis.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para produção (sem detalhes técnicos), criptografe dados em repouso e em trânsito, revise permissões de arquivos e endpoints, e monitore o que é expostos em respostas HTTP e logs.

CVE-2026-40281CRITICALGotenberg vulnerable to argument injection via newlines in ExifTool metadata valuesEPSS 0.6%CVE-2025-32458HIGHON Semiconductor Quantenna router_command.sh (in the get_syslog_from_qtn argument) Argument InjectionEPSS 0.6%CVE-2025-32457HIGHON Semiconductor Quantenna router_command.sh (in the get_file_from_qtn argument) Argument InjectionEPSS 0.6%CVE-2020-3380HIGHCisco Data Center Network Manager Privilege Escalation VulnerabilityEPSS 0.6%CVE-2025-32456HIGHON Semiconductor Quantenna router_command.sh (in the put_file_to_qtn argument) Argument InjectionEPSS 0.6%CVE-2019-5013HIGHAn exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the start/stopLauncEPSS 0.6%CVE-2025-3459HIGHON Semiconductor Quantenna transmit_file Argument InjectionEPSS 0.6%CVE-2024-21533MEDIUMAll versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specifying the remote URL EPSS 0.6%CVE-2025-32459HIGHON Semiconductor Quantenna router_command.sh (in the sync_time argument) Argument InjectionEPSS 0.6%CVE-2025-32455HIGHON Semiconductor Quantenna router_command.sh (in the run_cmd argument) Argument InjectionEPSS 0.6%CVE-2025-49008CRITICALAtheos Improper Input Validation Vulnerability Enables RCE in Common.phpEPSS 0.6%CVE-2025-59489HIGHUnity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code fEPSS 0.6%CVE-2021-21384MEDIUMNull characters not escaped in shescapeEPSS 0.6%CVE-2026-42284HIGHGitPython: Unsafe option check validates multi_options before shlex.split transforms itEPSS 0.6%CVE-2026-76220HIGHGitPython before 3.1.58 Command Execution via split_single_char_optionsEPSS 0.6%CVE-2026-73294CRITICALSemaphore U: OS Command InjectionEPSS 0.6%CVE-2022-46883HIGHMozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in FirEPSS 0.6%CVE-2025-49520HIGHEvent-driven-ansible: authenticated argument injection in git url in eda project creationEPSS 0.6%CVE-2025-61731HIGHArbitrary file write using cgo pkg-config directive in cmd/goEPSS 0.6%CVE-2026-65770CRITICALAzure Managed Instance for Apache Cassandra Remote Code Execution VulnerabilityEPSS 0.6%