Weaknesses of type CWE-88

311 results

Divulgação de Informações

Ocorre quando um programa expõe dados sensíveis (credenciais, tokens, caminhos internos, versões de sistemas) a usuários ou processos não autorizados. O risco está na falta de controle sobre quem acessa o quê, permitindo que informações confidenciais sejam lidas ou inferidas por atacantes.

Example

Um servidor web retorna mensagens de erro detalhadas que revelam a estrutura do banco de dados, ou uma API expõe UUIDs internos de usuários em respostas públicas, ou logs de aplicação contêm senhas armazenadas de forma legível em arquivos acessíveis.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para produção (sem detalhes técnicos), criptografe dados em repouso e em trânsito, revise permissões de arquivos e endpoints, e monitore o que é expostos em respostas HTTP e logs.

CVE-2026-6437MEDIUMAWS EFS CSI Driver Mount Option InjectionEPSS 0.5%CVE-2026-0634HIGHCode Execution in AssistFeedbackService on TECNO Pova7 Pro 5GEPSS 0.5%CVE-2024-2422CRITICALLenelS2 NetBox Improper Neutralization of Argumented DelimitersEPSS 0.5%CVE-2026-53790CRITICALrsync < 3.5.0 Command Injection via Multiple Code PathsEPSS 0.5%CVE-2024-32884MEDIUMgix-transport indirect code execution via malicious usernameEPSS 0.5%CVE-2024-52011HIGHlaunch-editor vulnerable to command injection via the crafted request on WindowsEPSS 0.5%CVE-2024-32462HIGHFlatpak vulnerable to a sandbox escape via RequestBackground portal due to bad argument parsingEPSS 0.5%CVE-2026-26194HIGHGogs: Release tag option injection in release deletionEPSS 0.5%CVE-2026-52750HIGHGhidra < 12.1- Command Injection via URL Annotation ClickEPSS 0.5%CVE-2026-44210MEDIUMKata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod AnnotationsEPSS 0.5%CVE-2026-43893HIGHexiftool-vendored: Argument injection via newline characters in tag namesEPSS 0.5%CVE-2023-30577HIGHAMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for runtar.c, a differentEPSS 0.5%CVE-2022-4864MEDIUM Argument Injection in froxlor/froxlorEPSS 0.5%CVE-2026-24126MEDIUMWeblate has an argument injection in management consoleEPSS 0.5%CVE-2025-12556HIGHIDIS ICM Viewer Argument InjectionEPSS 0.5%CVE-2026-44449CRITICALLumiverse: SMB `exists()` basename injection via smbclient `!cmd` escapeEPSS 0.5%CVE-2024-31966MEDIUMA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.4%CVE-2026-54337CRITICALFireshare has Unauthenticated Argument Injection to Arbitrary File Write/OverwriteEPSS 0.4%CVE-2026-76866HIGHNetcore NR255-V 1.5.130703 OS Command Argument Injection via Unquoted DDNS ParametersEPSS 0.4%CVE-2026-16770CRITICALPDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source documentEPSS 0.4%