Weaknesses of type CWE-88

311 results

Divulgação de Informações

Ocorre quando um programa expõe dados sensíveis (credenciais, tokens, caminhos internos, versões de sistemas) a usuários ou processos não autorizados. O risco está na falta de controle sobre quem acessa o quê, permitindo que informações confidenciais sejam lidas ou inferidas por atacantes.

Example

Um servidor web retorna mensagens de erro detalhadas que revelam a estrutura do banco de dados, ou uma API expõe UUIDs internos de usuários em respostas públicas, ou logs de aplicação contêm senhas armazenadas de forma legível em arquivos acessíveis.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para produção (sem detalhes técnicos), criptografe dados em repouso e em trânsito, revise permissões de arquivos e endpoints, e monitore o que é expostos em respostas HTTP e logs.

CVE-2026-32304CRITICALLocutus: RCE via unsanitized input in create_function()EPSS 0.6%CVE-2025-32931CRITICALDevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands vEPSS 0.6%CVE-2025-0065HIGHImproper Neutralization of Argument Delimiters in TeamViewer ClientsEPSS 0.6%CVE-2026-31230CRITICALThe Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robEPSS 0.6%CVE-2026-46483LOWVim: Command injection in tar#Vimuntar via missing shellescape {special} flagEPSS 0.6%CVE-2024-41711MEDIUMA vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (EPSS 0.5%CVE-2026-12856HIGHVscode-java: vscode: command injection vulnerability in the javadoc hover provider of the vscode-java extensionEPSS 0.5%CVE-2025-59937HIGHgo-mail has insufficient address encoding when passing mail addresses to the SMTP clientEPSS 0.5%CVE-2026-73240CRITICALApache Allura: Git command injectionEPSS 0.5%CVE-2026-49987HIGHRepomix: Command Injection (RCE) via `--remote-branch` Argument InjectionEPSS 0.5%CVE-2025-46835HIGHGit GUI can create and overwrite files for which the user has write permissionEPSS 0.5%CVE-2026-44189HIGHAnsible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execution via malicious playbook filenameEPSS 0.5%CVE-2026-25689MEDIUMAn improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.2.0, FortiDeEPSS 0.5%CVE-2022-44731MEDIUMA vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions < V3.15 P038), SIMATIC WinCC OA V3.16 (All versions < V3.16 P035EPSS 0.5%CVE-2026-45158CRITICALOPNsense: Command Injection via Attacker-Controlled DHCP ConfigEPSS 0.5%CVE-2026-44790CRITICALn8n: Arbitrary File Read via Git NodeEPSS 0.5%CVE-2022-37005HIGHThe Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentialEPSS 0.5%CVE-2019-5012HIGHAn exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the startProcess coEPSS 0.5%CVE-2026-46529HIGHPDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenEPSS 0.5%CVE-2026-6437MEDIUMAWS EFS CSI Driver Mount Option InjectionEPSS 0.5%