Falhas do tipo CWE-359
213 resultadosViolação de Privacidade
É quando um sistema expõe informações sensíveis de usuários (dados pessoais, credenciais, histórico de atividades) para quem não deveria ter acesso. Pode ocorrer por falha em controle de acesso, logs inadequados, cache inseguro ou falta de criptografia em trânsito/repouso.
Exemplo
Uma API REST que retorna email e CPF de outros usuários ao consultar um endpoint de perfil sem validar se o solicitante tem permissão; ou um sistema que registra senhas em log de erro visível aos administradores.
Como mitigar
Implemente controle de acesso rigoroso (verifique permissão antes de expor dados), evite armazenar dados sensíveis em logs/cache, criptografe dados em repouso e em trânsito (HTTPS, TLS), e aplique princípio de menor privilégio nas queries de banco de dados.
CVE-2025-54124HIGHXWiki Platform: Any user with editing rights can access password properties through Database List PropertiesEPSS 0.4%CVE-2024-42494HIGHRuijie Reyee OS Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.4%CVE-2026-28906HIGHThis issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, mEPSS 0.4%CVE-2026-57960HIGHHi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_idEPSS 0.4%CVE-2025-65857HIGHAn issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSEPSS 0.4%CVE-2024-42347HIGHURL preview setting for a room is controllable by the homeserver in matrix-react-sdkEPSS 0.4%CVE-2024-37136MEDIUMDell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Actor vulnerability. AEPSS 0.4%CVE-2026-48615MEDIUMA flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages.
When proxy credentialsEPSS 0.4%CVE-2025-31276MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Remote content mEPSS 0.4%CVE-2024-6053MEDIUMImproper access control in the clipboard synchronization featureEPSS 0.4%CVE-2025-59843MEDIUMFlagForgeCTF Exposes User Emails via Public /api/user/[username] APIEPSS 0.4%CVE-2024-12041MEDIUMDirectorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated User Information ExposureEPSS 0.4%CVE-2026-25699MEDIUMApache Answer: Authorization Bypass in Timeline APIEPSS 0.4%CVE-2026-50657MEDIUMMicrosoft Defender for Endpoint for Mac Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-54264HIGHAngular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service WorkerEPSS 0.4%CVE-2025-20060HIGHDario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.4%CVE-2025-0969MEDIUMBrizy – Page Builder <= 2.7.16 - Authenticated (Contributor+) Sensitive Information Exposure via get_users FunctionEPSS 0.4%CVE-2026-49344HIGHMercator has a Personal Identifiable Information Leak from Query Executor featureEPSS 0.4%CVE-2024-11206HIGHUnauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.EPSS 0.4%CVE-2024-13217MEDIUMJeg Elementor Kit <= 2.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via Countdown and Off-CanvasEPSS 0.4%