Fallos del tipo CWE-359

213 resultados

Violação de Privacidade

Ocorre quando a aplicação expõe dados pessoais ou sensíveis sem consentimento do usuário, ou com controle de acesso inadequado. O risco é que informações privadas (credenciais, dados financeiros, localização, etc.) fiquem acessíveis a quem não deveria ter acesso.

Ejemplo

Uma API retorna token de sessão, ID de usuário ou dados de perfil em URLs, logs públicos, ou respostas de erro visíveis; ou um endpoint de listar usuários não valida permissões, permitindo qualquer cliente enumerar dados sensíveis de terceiros.

Cómo mitigar

Implemente controle de acesso granular em cada endpoint sensível; nunca exponha dados pessoais em URLs, logs ou respostas de erro; criptografe dados em trânsito e em repouso; aplique princípio do menor privilégio e audite acessos regularmente.

CVE-2026-26237MEDIUMQuMagieEPSS 0.3%CVE-2025-62362MEDIUMName and e-mail of employee that has done a publication is discoverable in gpp-burgerportaalEPSS 0.3%CVE-2025-49134LOWWeblate exposes personal IP address via e-mailEPSS 0.3%CVE-2025-0679MEDIUMExposure of Private Personal Information to an Unauthorized Actor in GitLabEPSS 0.3%CVE-2020-1688MEDIUMJunos OS: SRX and NFX Series: Insufficient Web API private key protectionEPSS 0.3%CVE-2024-13216MEDIUMHT Event – WordPress Event Manager Plugin for Elementor <= 1.4.7 - Authenticated (Contributor+) Sensitive Information Exposure via HT Event: SponsorEPSS 0.3%CVE-2024-8891MEDIUMExposure of Private Personal Information to an Unauthorized Actor vulnerability on CIRCUTOR Q-SMTEPSS 0.3%CVE-2023-45720MEDIUMHCL Leap is affected by a disclosure of private personal information vulnerabilityEPSS 0.3%CVE-2025-1030HIGHSensitive Data Exposure in Utarit Informatics' SoliClubEPSS 0.3%CVE-2026-84606HIGHA privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visiEPSS 0.3%CVE-2024-11216HIGHBroken Access Control in PozitifIK's Pik OnlineEPSS 0.3%CVE-2026-61588MEDIUMdjust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the clientEPSS 0.3%CVE-2023-45721MEDIUMHCL Domino Volt and Domino Leap are affected by a disclosure of private personal information vulnerabilityEPSS 0.3%CVE-2024-42325LOWExcessive information returned by user.getEPSS 0.3%CVE-2026-53497MEDIUMCrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active session metadata (IP, User-Agent, session IDs)EPSS 0.3%CVE-2025-14317HIGHUser Enumeration in Crazy Bubble Tea mobile applicationEPSS 0.3%CVE-2025-43259MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, mEPSS 0.3%CVE-2025-3035MEDIUMTab title disclosure across pages when using AI chatbotEPSS 0.3%CVE-2026-28938HIGHA privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint tEPSS 0.3%CVE-2025-11959HIGHImproper Access Control in Premierturk's Excavation Management Information SystemEPSS 0.3%