Fallos del tipo CWE-88

311 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2026-6437MEDIUMAWS EFS CSI Driver Mount Option InjectionEPSS 0.5%CVE-2026-0634HIGHCode Execution in AssistFeedbackService on TECNO Pova7 Pro 5GEPSS 0.5%CVE-2024-2422CRITICALLenelS2 NetBox Improper Neutralization of Argumented DelimitersEPSS 0.5%CVE-2026-53790CRITICALrsync < 3.5.0 Command Injection via Multiple Code PathsEPSS 0.5%CVE-2024-32884MEDIUMgix-transport indirect code execution via malicious usernameEPSS 0.5%CVE-2024-52011HIGHlaunch-editor vulnerable to command injection via the crafted request on WindowsEPSS 0.5%CVE-2024-32462HIGHFlatpak vulnerable to a sandbox escape via RequestBackground portal due to bad argument parsingEPSS 0.5%CVE-2026-26194HIGHGogs: Release tag option injection in release deletionEPSS 0.5%CVE-2026-52750HIGHGhidra < 12.1- Command Injection via URL Annotation ClickEPSS 0.5%CVE-2026-44210MEDIUMKata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod AnnotationsEPSS 0.5%CVE-2026-43893HIGHexiftool-vendored: Argument injection via newline characters in tag namesEPSS 0.5%CVE-2023-30577HIGHAMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for runtar.c, a differentEPSS 0.5%CVE-2022-4864MEDIUM Argument Injection in froxlor/froxlorEPSS 0.5%CVE-2026-24126MEDIUMWeblate has an argument injection in management consoleEPSS 0.5%CVE-2025-12556HIGHIDIS ICM Viewer Argument InjectionEPSS 0.5%CVE-2026-44449CRITICALLumiverse: SMB `exists()` basename injection via smbclient `!cmd` escapeEPSS 0.5%CVE-2024-31966MEDIUMA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.4%CVE-2026-54337CRITICALFireshare has Unauthenticated Argument Injection to Arbitrary File Write/OverwriteEPSS 0.4%CVE-2026-76866HIGHNetcore NR255-V 1.5.130703 OS Command Argument Injection via Unquoted DDNS ParametersEPSS 0.4%CVE-2026-16770CRITICALPDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source documentEPSS 0.4%