Fallos del tipo CWE-88

311 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2026-44450CRITICALLumiverse: RCE via MCP stdio argument injectionEPSS 0.4%CVE-2026-17347HIGHpgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitutionEPSS 0.4%CVE-2026-53783HIGHrsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsyncEPSS 0.4%CVE-2026-86864HIGHpgAdmin 4: Argument and connection-string injection via the database field in the Backup toolEPSS 0.4%CVE-2026-28197CRITICALPrivilege Escalation via Argument Injection in NetBackup Flex OS ShellEPSS 0.4%CVE-2025-47421HIGHPrivilege escalation via SCP loginEPSS 0.4%CVE-2026-48116HIGHAnythingLLM: RCE via ripgrep --pre argument injection in filesystem-search-files agent skillEPSS 0.4%CVE-2025-12613HIGHVersions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing of parameter values cEPSS 0.4%CVE-2026-63046HIGHApache InLong: Agent Installer — Command Injection to RCE via Default CredentialsEPSS 0.4%CVE-2026-12530HIGHImproper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()EPSS 0.3%CVE-2025-23073LOWAPI list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets parameterEPSS 0.3%CVE-2026-35538LOWAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injectioEPSS 0.3%CVE-2026-50147HIGHMetabase: Arbitrary File Read via MySQL Connection Property InjectionEPSS 0.3%CVE-2026-73624HIGHGitPython before 3.1.54 Arbitrary File Overwrite via diffEPSS 0.3%CVE-2026-20016MEDIUMA vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authentEPSS 0.3%CVE-2025-43905MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 releasEPSS 0.3%CVE-2026-2449CRITICALImproper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions upKeeper Instant PrivEPSS 0.3%CVE-2026-90809MEDIUMHKUDS nanobot ExecTool shell.py ExecTool._spawn argument injectionEPSS 0.3%CVE-2026-78637MEDIUMFdawgs node-poppler Argument Injection index.js pdfUnite argument injectionEPSS 0.3%CVE-2020-27129MEDIUMCisco SD-WAN vManage Software Command Injection VulnerabilityEPSS 0.3%