Falhas do tipo CWE-347

642 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2025-68925MEDIUMJervis has a JWT Algorithm Confusion VulnerabilityEPSS 0.1%CVE-2025-59324CRITICALCPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPEPSS 0.1%CVE-2024-8036MEDIUMUnauthorized Modifications of Firmware and ConfigurationEPSS 0.1%CVE-2026-28432HIGHHTTP signature verification can be bypassedEPSS 0.1%CVE-2022-28752HIGHLocal Privilege Escalation in the Zoom Rooms for Windows ClientEPSS 0.1%CVE-2026-41694LOWSAML Payloads Decrypted Without Valid SignatureEPSS 0.1%CVE-2026-1568CRITICALRapid7 InsightVM Signature Validation VulnerabilityEPSS 0.1%CVE-2026-5466HIGHwc_VerifyEccsiHash missing sanity checkEPSS 0.1%CVE-2026-55961HIGHwolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signerEPSS 0.1%CVE-2023-43611HIGHBIG-IP Edge Client for macOS vulnerabilityEPSS 0.1%CVE-2024-54126HIGHInsufficient Integrity Verification Vulnerability in TP-Link Archer C50EPSS 0.1%CVE-2026-81680CRITICALopenssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot RemovalEPSS 0.1%CVE-2026-82955CRITICALIn the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API GaEPSS 0.1%CVE-2023-38418HIGHBIG-IP Edge Client for macOS vulnerabilityEPSS 0.1%CVE-2026-7689MEDIUMDolibarr ERP CRM Online Signature security.lib.php dol_verifyHash signature verificationEPSS 0.1%CVE-2026-79389HIGHTrueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modifEPSS 0.1%CVE-2026-42743MEDIUMWordPress Masteriyo - LMS plugin <= 2.1.8 - Broken Authentication vulnerabilityEPSS 0.1%CVE-2026-94368HIGHNoobaa-core: noobaa-core: presigned put url escalation to copyobject via unsigned x-amz-copy-source headerEPSS 0.1%CVE-2026-12860HIGHRSA PKCS#1 verification skips last two hash bytes in NULL-omitted pathEPSS 0.1%CVE-2026-34155HIGHRAUC: Improper Signing of Plain Bundles Exceeding 2 GiBEPSS 0.1%