Fallos del tipo CWE-88

311 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2026-40281CRITICALGotenberg vulnerable to argument injection via newlines in ExifTool metadata valuesEPSS 0.6%CVE-2025-32458HIGHON Semiconductor Quantenna router_command.sh (in the get_syslog_from_qtn argument) Argument InjectionEPSS 0.6%CVE-2025-32457HIGHON Semiconductor Quantenna router_command.sh (in the get_file_from_qtn argument) Argument InjectionEPSS 0.6%CVE-2020-3380HIGHCisco Data Center Network Manager Privilege Escalation VulnerabilityEPSS 0.6%CVE-2025-32456HIGHON Semiconductor Quantenna router_command.sh (in the put_file_to_qtn argument) Argument InjectionEPSS 0.6%CVE-2019-5013HIGHAn exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the start/stopLauncEPSS 0.6%CVE-2025-3459HIGHON Semiconductor Quantenna transmit_file Argument InjectionEPSS 0.6%CVE-2024-21533MEDIUMAll versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specifying the remote URL EPSS 0.6%CVE-2025-32459HIGHON Semiconductor Quantenna router_command.sh (in the sync_time argument) Argument InjectionEPSS 0.6%CVE-2025-32455HIGHON Semiconductor Quantenna router_command.sh (in the run_cmd argument) Argument InjectionEPSS 0.6%CVE-2025-49008CRITICALAtheos Improper Input Validation Vulnerability Enables RCE in Common.phpEPSS 0.6%CVE-2025-59489HIGHUnity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code fEPSS 0.6%CVE-2021-21384MEDIUMNull characters not escaped in shescapeEPSS 0.6%CVE-2026-42284HIGHGitPython: Unsafe option check validates multi_options before shlex.split transforms itEPSS 0.6%CVE-2026-76220HIGHGitPython before 3.1.58 Command Execution via split_single_char_optionsEPSS 0.6%CVE-2026-73294CRITICALSemaphore U: OS Command InjectionEPSS 0.6%CVE-2022-46883HIGHMozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in FirEPSS 0.6%CVE-2025-49520HIGHEvent-driven-ansible: authenticated argument injection in git url in eda project creationEPSS 0.6%CVE-2025-61731HIGHArbitrary file write using cgo pkg-config directive in cmd/goEPSS 0.6%CVE-2026-65770CRITICALAzure Managed Instance for Apache Cassandra Remote Code Execution VulnerabilityEPSS 0.6%