Falhas do tipo CWE-359
213 resultadosViolação de Privacidade
É quando um sistema expõe informações sensíveis de usuários (dados pessoais, credenciais, histórico de atividades) para quem não deveria ter acesso. Pode ocorrer por falha em controle de acesso, logs inadequados, cache inseguro ou falta de criptografia em trânsito/repouso.
Exemplo
Uma API REST que retorna email e CPF de outros usuários ao consultar um endpoint de perfil sem validar se o solicitante tem permissão; ou um sistema que registra senhas em log de erro visível aos administradores.
Como mitigar
Implemente controle de acesso rigoroso (verifique permissão antes de expor dados), evite armazenar dados sensíveis em logs/cache, criptografe dados em repouso e em trânsito (HTTPS, TLS), e aplique princípio de menor privilégio nas queries de banco de dados.
CVE-2025-3950LOWExposure of Private Personal Information to an Unauthorized Actor in GitLabEPSS 0.3%CVE-2026-55496MEDIUMCloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicateEPSS 0.3%CVE-2024-44113MEDIUMInformation Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer)EPSS 0.3%CVE-2024-41729MEDIUMInformation Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer)EPSS 0.3%CVE-2025-15623CRITICALSparx Pro Cloud Server reveals sensitive information to an unauthenticated userEPSS 0.3%CVE-2026-74966HIGHInformation disclosure in the Form Autofill componentEPSS 0.3%CVE-2026-86904HIGHA privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOSEPSS 0.3%CVE-2024-49386MEDIUMSensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0EPSS 0.2%CVE-2024-37533LOWIBM InfoSphere Information Server information disclosureEPSS 0.2%CVE-2025-20615MEDIUMQardio Heart Health IOS Mobile Application Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.2%CVE-2025-43357MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOEPSS 0.2%CVE-2023-25632—The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.EPSS 0.2%CVE-2025-43301LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma EPSS 0.2%CVE-2025-10450HIGHExposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.EPSS 0.2%CVE-2025-24355HIGHUpdatecli may expose Maven credentials in console outputEPSS 0.2%CVE-2025-13477HIGHOTP Bypass in Digital Operation Services' WifiBuradaEPSS 0.2%CVE-2026-88875MEDIUMAVideo Incomplete API Sanitization Information DisclosureEPSS 0.2%CVE-2026-24321MEDIUMInformation Disclosure vulnerability in SAP Commerce CloudEPSS 0.2%CVE-2025-43452MEDIUMThis issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 26.1 and iPadOS 26.1. Keyboard suggesEPSS 0.2%CVE-2026-6765MEDIUMInformation disclosure in the Form Autofill componentEPSS 0.2%