Falhas do tipo CWE-359
213 resultadosViolação de Privacidade
É quando um sistema expõe informações sensíveis de usuários (dados pessoais, credenciais, histórico de atividades) para quem não deveria ter acesso. Pode ocorrer por falha em controle de acesso, logs inadequados, cache inseguro ou falta de criptografia em trânsito/repouso.
Exemplo
Uma API REST que retorna email e CPF de outros usuários ao consultar um endpoint de perfil sem validar se o solicitante tem permissão; ou um sistema que registra senhas em log de erro visível aos administradores.
Como mitigar
Implemente controle de acesso rigoroso (verifique permissão antes de expor dados), evite armazenar dados sensíveis em logs/cache, criptografe dados em repouso e em trânsito (HTTPS, TLS), e aplique princípio de menor privilégio nas queries de banco de dados.
CVE-2024-4767MEDIUMIf the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. ThisEPSS 0.5%CVE-2025-43496HIGHThe issue was addressed by adding additional logic. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS SeqEPSS 0.5%CVE-2025-43500HIGHA privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1,EPSS 0.5%CVE-2025-53765MEDIUMAzure Stack Hub Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-13008HIGHSession Token Disclosure in M-Files WebEPSS 0.5%CVE-2026-0102LOWMicrosoft Edge (Chromium-based) Defense in Depth VulnerabilityEPSS 0.5%CVE-2024-33271HIGHAn issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_customer component.EPSS 0.5%CVE-2024-53258HIGHdownload_all_submissions allows student to download another student's submissions in AutolabEPSS 0.5%CVE-2024-11712MEDIUMWP Job Portal <= 2.2.2 - Missing Authorization to Unauthenticated Arbitrary Resume DownloadEPSS 0.5%CVE-2023-34085LOWUser Attribute Disclosure via DynamoDB Data StoresEPSS 0.5%CVE-2026-73008MEDIUMWindows Biometric Service Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-34226HIGHHappy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookiesEPSS 0.5%CVE-2026-69351MEDIUMWindows Universal Plug and Play (UPnP) Device Host Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-62644MEDIUMThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal informatioEPSS 0.5%CVE-2024-38103MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-28387HIGHAn issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.EPSS 0.4%CVE-2025-53625HIGHDynamicPageList3 exposes hidden/suppressed usernamesEPSS 0.4%CVE-2024-45787HIGHInformation Disclosure VulnerabilityEPSS 0.4%CVE-2024-47085HIGHParameter Manipulation VulnerabilityEPSS 0.4%CVE-2024-47087HIGHInformation Disclosure VulnerabilityEPSS 0.4%