Fallos del tipo CWE-88

311 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2025-6232HIGHAn improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute coEPSS 0.2%CVE-2025-67858HIGHA crafted "interface" input parameter can lead to integrity loss of the firewall configurationEPSS 0.2%CVE-2026-11968MEDIUMImproper Neutralization of Argument Delimiters in a Command ('Argument Injection') in TortoiseGitEPSS 0.2%CVE-2026-64624HIGHFreeRDP RDP File Parser Remote Code Execution via CLI OptionsEPSS 0.2%CVE-2026-16493HIGHAnsible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for cve-2026-11332)EPSS 0.2%CVE-2026-81529HIGHConnection-option injection via unescaped settings in the canonical MongoDB URL builderEPSS 0.2%CVE-2026-68939LOWPyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)EPSS 0.2%CVE-2026-43943HIGHelecterm: RCE via malicious SSH server filename in openFileWithEditorEPSS 0.2%CVE-2026-68766HIGHhashcat through 7.1.2 Arbitrary File Write via Restore File Option InjectionEPSS 0.2%CVE-2025-41761HIGHPrivilege escalation possibleEPSS 0.2%CVE-2026-94588MEDIUMIn Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper EPSS 0.2%CVE-2026-45181MEDIUMHex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers EPSS 0.2%CVE-2026-89066HIGHOS command injection in the task synthesis component in projenEPSS 0.2%CVE-2026-78635MEDIUMImproper Input Validation in the Okta Privileged Access SSH Client URL Handler ArgumentEPSS 0.2%CVE-2026-44712HIGHpam_usb: Shell injection via device UUID and username in pamusb-conf and pamusb-agentEPSS 0.2%CVE-2025-66002MEDIUMLocal users can perform arbitrary unmounts via smb4k mount helper due to lack of input validationEPSS 0.2%CVE-2026-80427HIGHbestzip before 2.2.6 and 3.0.x before 3.0.2 Argument Injection via Missing Option DelimiterEPSS 0.2%CVE-2026-93337HIGHNetworkManager-l2tp Privilege Escalation via pppd Plugin InjectionEPSS 0.1%CVE-2026-90894HIGHParallels Desktop local privilege escalation via appliance extract argument injectionEPSS 0.1%CVE-2026-1716MEDIUMAn input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow aEPSS 0.1%