Fallos del tipo CWE-359

213 resultados

Violação de Privacidade

Ocorre quando a aplicação expõe dados pessoais ou sensíveis sem consentimento do usuário, ou com controle de acesso inadequado. O risco é que informações privadas (credenciais, dados financeiros, localização, etc.) fiquem acessíveis a quem não deveria ter acesso.

Ejemplo

Uma API retorna token de sessão, ID de usuário ou dados de perfil em URLs, logs públicos, ou respostas de erro visíveis; ou um endpoint de listar usuários não valida permissões, permitindo qualquer cliente enumerar dados sensíveis de terceiros.

Cómo mitigar

Implemente controle de acesso granular em cada endpoint sensível; nunca exponha dados pessoais em URLs, logs ou respostas de erro; criptografe dados em trânsito e em repouso; aplique princípio do menor privilégio e audite acessos regularmente.

CVE-2025-54124HIGHXWiki Platform: Any user with editing rights can access password properties through Database List PropertiesEPSS 0.4%CVE-2024-42494HIGHRuijie Reyee OS Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.4%CVE-2026-28906HIGHThis issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, mEPSS 0.4%CVE-2026-57960HIGHHi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_idEPSS 0.4%CVE-2025-65857HIGHAn issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSEPSS 0.4%CVE-2024-42347HIGHURL preview setting for a room is controllable by the homeserver in matrix-react-sdkEPSS 0.4%CVE-2024-37136MEDIUMDell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Actor vulnerability. AEPSS 0.4%CVE-2026-48615MEDIUMA flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentialsEPSS 0.4%CVE-2025-31276MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Remote content mEPSS 0.4%CVE-2024-6053MEDIUMImproper access control in the clipboard synchronization featureEPSS 0.4%CVE-2025-59843MEDIUMFlagForgeCTF Exposes User Emails via Public /api/user/[username] APIEPSS 0.4%CVE-2024-12041MEDIUMDirectorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated User Information ExposureEPSS 0.4%CVE-2026-25699MEDIUMApache Answer: Authorization Bypass in Timeline APIEPSS 0.4%CVE-2026-50657MEDIUMMicrosoft Defender for Endpoint for Mac Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-54264HIGHAngular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service WorkerEPSS 0.4%CVE-2025-20060HIGHDario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.4%CVE-2025-0969MEDIUMBrizy – Page Builder <= 2.7.16 - Authenticated (Contributor+) Sensitive Information Exposure via get_users FunctionEPSS 0.4%CVE-2026-49344HIGHMercator has a Personal Identifiable Information Leak from Query Executor featureEPSS 0.4%CVE-2024-11206HIGHUnauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.EPSS 0.4%CVE-2024-13217MEDIUMJeg Elementor Kit <= 2.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-CanvasEPSS 0.4%