Falhas do tipo CWE-88

311 resultados

Divulgação de Informações

Falha que permite que dados sensíveis (senhas, tokens, chaves, dados pessoais) sejam expostos a usuários ou atacantes que não deveriam ter acesso. O código não implementa controles adequados de acesso ou deixa informações sensíveis visíveis em logs, mensagens de erro, respostas HTTP ou memória.

Exemplo

Um servidor retorna mensagens de erro detalhadas que revelam estrutura do banco de dados, caminhos de arquivos ou nomes de usuários válidos. Ou uma API expõe dados de usuários em resposta JSON sem validar permissões, permitindo qualquer cliente listar informações alheias.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para não expor detalhes internos, revise logs e respostas da API antes de enviar ao cliente, criptografe dados em repouso e em trânsito. Teste regularmente com ferramentas de fuzzing e análise de dados expostos.

CVE-2021-1485MEDIUMCisco IOS XR Software Command Injection VulnerabilityEPSS 0.3%CVE-2026-35033CRITICALJellyfin: Potential SSRF + Arbitrary file read via stream argument injectionEPSS 0.3%CVE-2026-50014MEDIUMpnpm: Git Fetch Argument Injection via Lockfile resolution.commitEPSS 0.3%CVE-2026-4438MEDIUMgethostbyaddr and gethostbyaddr_r return invalid DNS hostnamesEPSS 0.3%CVE-2024-3367MEDIUMArgument injection to runmqscEPSS 0.3%CVE-2026-71377CRITICALCommand Argument Injection Vulnerability in Cosminexus Component ContainerEPSS 0.3%CVE-2026-4519HIGHwebbrowser.open() allows leading dashes in URLsEPSS 0.3%CVE-2026-76212MEDIUMphpMyFAQ before 4.1.7 LIKE Wildcard Injection via PostgreSQLEPSS 0.3%CVE-2025-53509HIGHAdvantech iView Argument InjectionEPSS 0.3%CVE-2026-76219HIGHGitPython before 3.1.58 Arbitrary File Overwrite via read-treeEPSS 0.3%CVE-2026-3515HIGHArgument Injection in prefecthq/prefectEPSS 0.3%CVE-2026-34769HIGHElectron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferenceEPSS 0.3%CVE-2026-4786HIGHIncomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()EPSS 0.3%CVE-2025-52459HIGHAdvantech iView Argument InjectionEPSS 0.3%CVE-2026-62867CRITICALIncus has an argument injection in storage volume block.create_options that leads to arbitrary command executionEPSS 0.3%CVE-2026-85626HIGHgit-mcp-server 2.15.1 Argument Injection via Git Ref ParametersEPSS 0.3%CVE-2023-0633HIGHIn Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in LPEEPSS 0.3%CVE-2026-29954HIGHIn KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of EPSS 0.3%CVE-2026-47250MEDIUMmcp-server-kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltrationEPSS 0.3%CVE-2024-51532HIGHDell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privilegEPSS 0.3%