Falhas do tipo CWE-88

311 resultados

Divulgação de Informações

Falha que permite que dados sensíveis (senhas, tokens, chaves, dados pessoais) sejam expostos a usuários ou atacantes que não deveriam ter acesso. O código não implementa controles adequados de acesso ou deixa informações sensíveis visíveis em logs, mensagens de erro, respostas HTTP ou memória.

Exemplo

Um servidor retorna mensagens de erro detalhadas que revelam estrutura do banco de dados, caminhos de arquivos ou nomes de usuários válidos. Ou uma API expõe dados de usuários em resposta JSON sem validar permissões, permitindo qualquer cliente listar informações alheias.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para não expor detalhes internos, revise logs e respostas da API antes de enviar ao cliente, criptografe dados em repouso e em trânsito. Teste regularmente com ferramentas de fuzzing e análise de dados expostos.

CVE-2026-8044HIGHCWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote codeEPSS 0.4%CVE-2026-78676CRITICALGitPython before 3.1.59 Remote Code Execution via Config InjectionEPSS 0.4%CVE-2026-55673HIGHPowSyBl: Command Injection in LocalCommandExecutor-sEPSS 0.4%CVE-2026-79675CRITICALNLTK before 3.10.3 JVM Argument Injection via Per-Call OptionsEPSS 0.4%CVE-2024-7573MEDIUMRelevanssi Live Ajax Search <= 2.4 - Unauthenticated WP_Query Argument InjectionEPSS 0.4%CVE-2026-76862HIGHNetcore NR255-V 1.5.130703 OS Command Argument Injection in Nettools tcpdump Launch PathsEPSS 0.4%CVE-2026-2298CRITICALImproper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement alEPSS 0.4%CVE-2026-47365CRITICALArgument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass croEPSS 0.4%CVE-2024-3775MEDIUMaEnrich Technology a+HRD - Argument InjectionEPSS 0.4%CVE-2026-75912HIGHCodeWhale before 0.8.64 Argument Injection via git_blameEPSS 0.4%CVE-2026-22168HIGHOpenClaw < 2026.2.21 - Command Injection via cmd.exe /c Trailing Arguments in system.runEPSS 0.4%CVE-2026-42601CRITICALArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddViewEPSS 0.4%CVE-2026-54686MEDIUMWarp: DCS lifecycle hook spoofing can alter terminal session metadataEPSS 0.4%CVE-2020-1738LOWA flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task iEPSS 0.4%CVE-2025-40948MEDIUMA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEEPSS 0.4%CVE-2025-27146LOWMatrix IRC Bridge allows IRC command injection to own puppeted userEPSS 0.4%CVE-2026-43941CRITICALUnvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link clickEPSS 0.4%CVE-2026-26514HIGHAn Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute module uses shlex.Split to parse user input wEPSS 0.4%CVE-2025-29768MEDIUMVim vulnerable to potential data loss with zip.vim and special crafted zip filesEPSS 0.4%CVE-2026-84256HIGHAn argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to exEPSS 0.4%