Falhas do tipo CWE-347

640 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2026-0750HIGHPayment bypass in Commerce PayboxEPSS 0.3%CVE-2026-33746CRITICALConvoy: JWT Signature Verification Bypass Allows Authentication as Arbitrary UsersEPSS 0.3%CVE-2026-11800HIGHOrg.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusionEPSS 0.3%CVE-2026-33487HIGHgoxmldsig has validateSignature Loop Variable Capture Signature BypassEPSS 0.3%CVE-2026-56864HIGHIgnore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdbEPSS 0.3%CVE-2021-43716CRITICALVerification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by enEPSS 0.3%CVE-2026-38651HIGHAuthentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validEPSS 0.3%CVE-2022-23507MEDIUMLight client verification not taking into account chain IDEPSS 0.3%CVE-2026-62834CRITICALAzure Data Factory Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-81701CRITICALopenssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned pluginEPSS 0.3%CVE-2026-3562MEDIUMPhilips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass VulnerabilityEPSS 0.3%CVE-2021-43074MEDIUMAn improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and below, 6.2 all versionsEPSS 0.3%CVE-2026-89043CRITICALpassport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion PrependingEPSS 0.3%CVE-2020-3209MEDIUMCisco IOS XE Software Digital Signature Verification Bypass VulnerabilityEPSS 0.3%CVE-2026-64623HIGHNetwork-AI before 5.13.4 Cryptographic Signature Verification BypassEPSS 0.3%CVE-2025-24015HIGHDeno's AES GCM authentication tags are not verifiedEPSS 0.3%CVE-2026-4478CRITICALYi Technology YI Home Camera HTTP Firmware Update ipc signature verificationEPSS 0.3%CVE-2026-10723MEDIUMIncorrect acceptance of NSEC3 recordsEPSS 0.3%CVE-2026-13722HIGHWatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OSEPSS 0.3%CVE-2026-89042CRITICALpassport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature VerificationEPSS 0.3%