Falhas do tipo CWE-88

311 resultados

Divulgação de Informações

Falha que permite que dados sensíveis (senhas, tokens, chaves, dados pessoais) sejam expostos a usuários ou atacantes que não deveriam ter acesso. O código não implementa controles adequados de acesso ou deixa informações sensíveis visíveis em logs, mensagens de erro, respostas HTTP ou memória.

Exemplo

Um servidor retorna mensagens de erro detalhadas que revelam estrutura do banco de dados, caminhos de arquivos ou nomes de usuários válidos. Ou uma API expõe dados de usuários em resposta JSON sem validar permissões, permitindo qualquer cliente listar informações alheias.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para não expor detalhes internos, revise logs e respostas da API antes de enviar ao cliente, criptografe dados em repouso e em trânsito. Teste regularmente com ferramentas de fuzzing e análise de dados expostos.

CVE-2026-44450CRITICALLumiverse: RCE via MCP stdio argument injectionEPSS 0.4%CVE-2026-17347HIGHpgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitutionEPSS 0.4%CVE-2026-53783HIGHrsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsyncEPSS 0.4%CVE-2026-86864HIGHpgAdmin 4: Argument and connection-string injection via the database field in the Backup toolEPSS 0.4%CVE-2026-28197CRITICALPrivilege Escalation via Argument Injection in NetBackup Flex OS ShellEPSS 0.4%CVE-2025-47421HIGHPrivilege escalation via SCP loginEPSS 0.4%CVE-2026-48116HIGHAnythingLLM: RCE via ripgrep --pre argument injection in filesystem-search-files agent skillEPSS 0.4%CVE-2025-12613HIGHVersions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing of parameter values cEPSS 0.4%CVE-2026-63046HIGHApache InLong: Agent Installer — Command Injection to RCE via Default CredentialsEPSS 0.4%CVE-2026-12530HIGHImproper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()EPSS 0.3%CVE-2025-23073LOWAPI list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets parameterEPSS 0.3%CVE-2026-35538LOWAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injectioEPSS 0.3%CVE-2026-50147HIGHMetabase: Arbitrary File Read via MySQL Connection Property InjectionEPSS 0.3%CVE-2026-73624HIGHGitPython before 3.1.54 Arbitrary File Overwrite via diffEPSS 0.3%CVE-2026-20016MEDIUMA vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authentEPSS 0.3%CVE-2025-43905MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 releasEPSS 0.3%CVE-2026-2449CRITICALImproper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions upKeeper Instant PrivEPSS 0.3%CVE-2026-90809MEDIUMHKUDS nanobot ExecTool shell.py ExecTool._spawn argument injectionEPSS 0.3%CVE-2026-78637MEDIUMFdawgs node-poppler Argument Injection index.js pdfUnite argument injectionEPSS 0.3%CVE-2020-27129MEDIUMCisco SD-WAN vManage Software Command Injection VulnerabilityEPSS 0.3%