Fallos del tipo CWE-88

311 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2026-16796HIGHImproper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()EPSS 0.7%CVE-2026-27947CRITICALGroup-Office Vulnerable to Remote Code Execution (RCE)EPSS 0.7%CVE-2020-7851HIGHInnorix File Transfer Solution File Download and Execution VulnerabilityEPSS 0.7%CVE-2026-76218HIGHGitPython before 3.1.58 Remote Code Execution via Repo.initEPSS 0.7%CVE-2026-89036HIGHAppwrite < 2.0.0 Argument Injection via providerRootDirectory ParameterEPSS 0.7%CVE-2026-47114HIGHIINA < 1.4.3 Command Execution via iina://open URL SchemeEPSS 0.7%CVE-2024-39933HIGHGogs through 0.13.0 allows argument injection during the tagging of a new release.EPSS 0.7%CVE-2026-72538HIGHPrefectHQ Prefect - Argument InjectionEPSS 0.7%CVE-2020-7808HIGHRAONWIZ Inc K Upload, arguments modiffication via missing support for integrity check vulnerabilityEPSS 0.7%CVE-2026-44193CRITICALOPNsense: RCE via XMLRPC endpoint using `opnsense.restore_config_section` methodEPSS 0.7%CVE-2026-48793HIGHJellyfin: Potential FFmpeg argument injection via unescaped subtitle file pathEPSS 0.7%CVE-2026-22582CRITICALImproper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MEPSS 0.7%CVE-2026-22583CRITICALImproper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CEPSS 0.7%CVE-2026-27208CRITICALapi-gateway-deploy Affected by Exploitable Command Injection via Unprivileged Root ExecutionEPSS 0.7%CVE-2025-3945HIGHImproper Neutralization of Argument Delimiters in a Command (‘Argument Injection’)EPSS 0.7%CVE-2022-36322MEDIUMIn JetBrains TeamCity before 2022.04.2 build parameter injection was possibleEPSS 0.6%CVE-2025-53542HIGHKubernetes Headlamp Allows Arbitrary Command Injection in macOS Process headlamp@codeSignEPSS 0.6%CVE-2025-52480HIGHRegistrator.jl Argument Injection VulnerabilityEPSS 0.6%CVE-2026-42266HIGHJupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.EPSS 0.6%CVE-2024-22182HIGHCommend WS203VICM Argument InjectionEPSS 0.6%