Fallos del tipo CWE-347

640 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2026-85995HIGHNotepad++: Authenticode verification bypass allows modified updater executionEPSS 0.1%CVE-2024-38807MEDIUMCVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's LoaderEPSS 0.1%CVE-2026-27445MEDIUMPGP Signature ReflectionEPSS 0.1%CVE-2025-27498MEDIUMAEADs/ascon-aead: Plaintext exposed in decrypt_in_place_detached even on tag verification failureEPSS 0.1%CVE-2025-34503HIGHShuffle Master Deck Mate 1 Unauthenticated EEPROM Firmware ExecutionEPSS 0.1%CVE-2022-4418HIGHLocal privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect HomEPSS 0.1%CVE-2026-13305MEDIUMAutel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution VulnerabilityEPSS 0.1%CVE-2023-32449HIGH Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a hiEPSS 0.1%CVE-2026-44309MEDIUMgitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commitsEPSS 0.1%CVE-2023-23431HIGH Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwritEPSS 0.1%CVE-2026-45575HIGHepa4all-client: Improper Verification of Cryptographic SignatureEPSS 0.1%CVE-2026-58262HIGHKlever-Go: PubKeysBitmap padding bits bypass the BLS signature quorumEPSS 0.1%CVE-2024-27247MEDIUMZoom Desktop Client for macOS - Improper Privilege ManagementEPSS 0.1%CVE-2025-43468MEDIUMA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2025-2866LOWPDF signature forgery with adbe.pkcs7.sha1 SubFilterEPSS 0.1%CVE-2026-63237MEDIUMTOTP two-factor authentication bypass vulnerabilityEPSS 0.1%CVE-2025-52648MEDIUMHCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverifieEPSS 0.1%CVE-2025-43522LOWA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2024-1150HIGHImproper validation of update packagesEPSS 0.1%CVE-2024-1149HIGHImproper validation of update packagesEPSS 0.1%