Fallos del tipo CWE-347

642 resultados

Divulgação de informações

Uma fraqueza que permite que dados sensíveis (credenciais, tokens, dados pessoais, detalhes técnicos do sistema) sejam expostos para um atacante ou usuário não autorizado. O risco é alto porque informações divulgadas podem ser usadas para escalar ataques ou comprometer a confidencialidade de dados críticos.

Ejemplo

Um aplicativo web que expõe stack traces com caminhos de arquivo e versões de banco de dados em mensagens de erro HTTP; ou uma API que retorna tokens JWT expirados em respostas de erro em texto plano; ou um arquivo de configuração deixado acessível publicamente contendo credenciais de banco de dados.

Cómo mitigar

Nunca exponha informações técnicas ou sensíveis em mensagens de erro, logs públicos ou respostas da aplicação — use mensagens genéricas para o usuário final. Implemente controle de acesso rigoroso, criptografe dados em repouso e em trânsito, e audite regularmente o que está sendo armazenado e acessível publicamente.

CVE-2024-2451MEDIUMImproper fingerprint validation in the TeamViewer ClientEPSS 0.1%CVE-2024-51526HIGHPermission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentialEPSS 0.1%CVE-2025-27813HIGHMSI Center before 2.0.52.0 has Missing PE Signature Validation.EPSS 0.1%CVE-2026-50719MEDIUMThe Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header beEPSS 0.1%CVE-2026-85525HIGHImproper OCSP response validation in Snowflake driversEPSS 0.1%CVE-2025-58356HIGHConstellation allows insecure use of LUKS2 persistent storage partitionsEPSS 0.1%CVE-2025-34324HIGHGoSign Desktop < 2.4.1 Insecure Update Mechanism RCEEPSS 0.1%CVE-2024-36347MEDIUMImproper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicEPSS 0.1%CVE-2023-20236MEDIUMA vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified sofEPSS 0.1%CVE-2024-27244MEDIUMZoom Workplace VDI App for Windows - Insufficient Verification of Data AuthenticityEPSS 0.1%CVE-2025-64740HIGHZoom Workplace VDI Client for Windows - Improper Verification of Cryptographic SignatureEPSS 0.1%CVE-2025-20248MEDIUMCisco IOS XR Software Image Verification Bypass VulnerabilityEPSS 0.1%CVE-2024-53267MEDIUMVulnerability with bundle verification in sigstore-javaEPSS 0.1%CVE-2026-45614MEDIUMOP-TEE vulnerable to ECDH private key recoveryEPSS 0.1%CVE-2026-50720MEDIUMThe Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32EPSS 0.1%CVE-2023-20135MEDIUMA vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code onEPSS 0.1%CVE-2026-81717CRITICALopenssl_encrypt before 1.4.9 Integrity Bypass via Added FilesEPSS 0.1%CVE-2024-23581MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerabilityEPSS 0.1%CVE-2026-82876CRITICALPhison PS3111-S11 Controller Firmware Signature Verification BypassEPSS 0.1%CVE-2026-84185MEDIUMJwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verificationEPSS 0.1%