Fallos del tipo CWE-88

311 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2026-8044HIGHCWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote codeEPSS 0.4%CVE-2026-78676CRITICALGitPython before 3.1.59 Remote Code Execution via Config InjectionEPSS 0.4%CVE-2026-79675CRITICALNLTK before 3.10.3 JVM Argument Injection via Per-Call OptionsEPSS 0.4%CVE-2026-55673HIGHPowSyBl: Command Injection in LocalCommandExecutor-sEPSS 0.4%CVE-2024-7573MEDIUMRelevanssi Live Ajax Search <= 2.4 - Unauthenticated WP_Query Argument InjectionEPSS 0.4%CVE-2026-76862HIGHNetcore NR255-V 1.5.130703 OS Command Argument Injection in Nettools tcpdump Launch PathsEPSS 0.4%CVE-2026-2298CRITICALImproper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement alEPSS 0.4%CVE-2026-47365CRITICALArgument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass croEPSS 0.4%CVE-2024-3775MEDIUMaEnrich Technology a+HRD - Argument InjectionEPSS 0.4%CVE-2026-75912HIGHCodeWhale before 0.8.64 Argument Injection via git_blameEPSS 0.4%CVE-2026-22168HIGHOpenClaw < 2026.2.21 - Command Injection via cmd.exe /c Trailing Arguments in system.runEPSS 0.4%CVE-2026-42601CRITICALArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddViewEPSS 0.4%CVE-2026-54686MEDIUMWarp: DCS lifecycle hook spoofing can alter terminal session metadataEPSS 0.4%CVE-2020-1738LOWA flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task iEPSS 0.4%CVE-2025-40948MEDIUMA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEEPSS 0.4%CVE-2025-27146LOWMatrix IRC Bridge allows IRC command injection to own puppeted userEPSS 0.4%CVE-2026-43941CRITICALUnvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link clickEPSS 0.4%CVE-2026-26514HIGHAn Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute module uses shlex.Split to parse user input wEPSS 0.4%CVE-2025-29768MEDIUMVim vulnerable to potential data loss with zip.vim and special crafted zip filesEPSS 0.4%CVE-2026-84256HIGHAn argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to exEPSS 0.4%