Fallos del tipo CWE-88

311 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2026-32304CRITICALLocutus: RCE via unsanitized input in create_function()EPSS 0.6%CVE-2025-32931CRITICALDevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands vEPSS 0.6%CVE-2025-0065HIGHImproper Neutralization of Argument Delimiters in TeamViewer ClientsEPSS 0.6%CVE-2026-31230CRITICALThe Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robEPSS 0.6%CVE-2026-46483LOWVim: Command injection in tar#Vimuntar via missing shellescape {special} flagEPSS 0.6%CVE-2024-41711MEDIUMA vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (EPSS 0.5%CVE-2026-12856HIGHVscode-java: vscode: command injection vulnerability in the javadoc hover provider of the vscode-java extensionEPSS 0.5%CVE-2025-59937HIGHgo-mail has insufficient address encoding when passing mail addresses to the SMTP clientEPSS 0.5%CVE-2026-73240CRITICALApache Allura: Git command injectionEPSS 0.5%CVE-2026-49987HIGHRepomix: Command Injection (RCE) via `--remote-branch` Argument InjectionEPSS 0.5%CVE-2025-46835HIGHGit GUI can create and overwrite files for which the user has write permissionEPSS 0.5%CVE-2026-44189HIGHAnsible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execution via malicious playbook filenameEPSS 0.5%CVE-2026-25689MEDIUMAn improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.2.0, FortiDeEPSS 0.5%CVE-2022-44731MEDIUMA vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions < V3.15 P038), SIMATIC WinCC OA V3.16 (All versions < V3.16 P035EPSS 0.5%CVE-2026-45158CRITICALOPNsense: Command Injection via Attacker-Controlled DHCP ConfigEPSS 0.5%CVE-2026-44790CRITICALn8n: Arbitrary File Read via Git NodeEPSS 0.5%CVE-2022-37005HIGHThe Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentialEPSS 0.5%CVE-2019-5012HIGHAn exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the startProcess coEPSS 0.5%CVE-2026-46529HIGHPDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenEPSS 0.5%CVE-2026-6437MEDIUMAWS EFS CSI Driver Mount Option InjectionEPSS 0.5%