Fallos del tipo CWE-88

311 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2021-1485MEDIUMCisco IOS XR Software Command Injection VulnerabilityEPSS 0.3%CVE-2026-35033CRITICALJellyfin: Potential SSRF + Arbitrary file read via stream argument injectionEPSS 0.3%CVE-2026-50014MEDIUMpnpm: Git Fetch Argument Injection via Lockfile resolution.commitEPSS 0.3%CVE-2026-4438MEDIUMgethostbyaddr and gethostbyaddr_r return invalid DNS hostnamesEPSS 0.3%CVE-2026-71377CRITICALCommand Argument Injection Vulnerability in Cosminexus Component ContainerEPSS 0.3%CVE-2024-3367MEDIUMArgument injection to runmqscEPSS 0.3%CVE-2026-4519HIGHwebbrowser.open() allows leading dashes in URLsEPSS 0.3%CVE-2026-76212MEDIUMphpMyFAQ before 4.1.7 LIKE Wildcard Injection via PostgreSQLEPSS 0.3%CVE-2025-53509HIGHAdvantech iView Argument InjectionEPSS 0.3%CVE-2026-76219HIGHGitPython before 3.1.58 Arbitrary File Overwrite via read-treeEPSS 0.3%CVE-2026-3515HIGHArgument Injection in prefecthq/prefectEPSS 0.3%CVE-2026-34769HIGHElectron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferenceEPSS 0.3%CVE-2026-4786HIGHIncomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()EPSS 0.3%CVE-2025-52459HIGHAdvantech iView Argument InjectionEPSS 0.3%CVE-2026-62867CRITICALIncus has an argument injection in storage volume block.create_options that leads to arbitrary command executionEPSS 0.3%CVE-2026-85626HIGHgit-mcp-server 2.15.1 Argument Injection via Git Ref ParametersEPSS 0.3%CVE-2023-0633HIGHIn Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in LPEEPSS 0.3%CVE-2026-29954HIGHIn KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of EPSS 0.3%CVE-2026-47250MEDIUMmcp-server-kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltrationEPSS 0.3%CVE-2024-51532HIGHDell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privilegEPSS 0.3%