Fallos del tipo CWE-88

311 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2020-7496A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formEPSS 0.9%CVE-2026-25134CRITICALGroup-Office Argument Injection in MaintenanceController::actionZipLanguageEPSS 0.8%CVE-2024-47553CRITICALA vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate uEPSS 0.8%CVE-2026-0774HIGHWatchYourLAN Configuration Page Argument Injection Remote Code Execution VulnerabilityEPSS 0.8%CVE-2025-62847MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2025-31499HIGHJellyfin Vulnerable to Argument Injection in FFmpegEPSS 0.8%CVE-2022-47926CRITICALAyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.phpEPSS 0.8%CVE-2021-3045MEDIUMPAN-OS: OS Command Argument Injection in Web InterfaceEPSS 0.8%CVE-2026-40938HIGHTekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCEEPSS 0.8%CVE-2026-52891CRITICALWekan: Shell Injection via Avatar UploadEPSS 0.8%CVE-2025-1712HIGHArbitrary file write with vcrtraceEPSS 0.8%CVE-2020-7850HIGHDouzone ActiveX File Download and Execution VulnerabilityEPSS 0.8%CVE-2022-40677HIGHA improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.EPSS 0.8%CVE-2026-54088CRITICALFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)EPSS 0.8%CVE-2023-34395HIGHApache Airflow ODBC Provider: Remote code execution vulnerabilityEPSS 0.8%CVE-2024-47611MEDIUMXZ Utils on Microsoft Windows platform are vulnerable to argument injectionEPSS 0.8%CVE-2024-20444MEDIUMCisco Nexus Dashboard Fabric Controller REST API Command Injection VulnerabilityEPSS 0.8%CVE-2026-7865HIGHHidden Console CommandEPSS 0.8%CVE-2026-27613CRITICALCGI Parameter Injection (Bypass of STRICT_CGI_PARAMS and EscapeShellParam)EPSS 0.7%CVE-2024-43402HIGHRust OS Command Injection/Argument Injection vulnerabilityEPSS 0.7%