Falhas do tipo CWE-88

311 resultados

Divulgação de Informações

Falha que permite que dados sensíveis (senhas, tokens, chaves, dados pessoais) sejam expostos a usuários ou atacantes que não deveriam ter acesso. O código não implementa controles adequados de acesso ou deixa informações sensíveis visíveis em logs, mensagens de erro, respostas HTTP ou memória.

Exemplo

Um servidor retorna mensagens de erro detalhadas que revelam estrutura do banco de dados, caminhos de arquivos ou nomes de usuários válidos. Ou uma API expõe dados de usuários em resposta JSON sem validar permissões, permitindo qualquer cliente listar informações alheias.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para não expor detalhes internos, revise logs e respostas da API antes de enviar ao cliente, criptografe dados em repouso e em trânsito. Teste regularmente com ferramentas de fuzzing e análise de dados expostos.

CVE-2026-39884HIGHMCP Server Kubernetes has Argument Injection in its port_forward tool via space-splittingEPSS 0.3%CVE-2026-7725MEDIUMPrefectHQ prefect GitRepository Pull storage.py argument injectionEPSS 0.2%CVE-2022-20930MEDIUMCisco SD-WAN Software Arbitrary File Corruption VulnerabilityEPSS 0.2%CVE-2026-8773MEDIUMlinlinjava litemall Database Setting DbUtil.java load argument injectionEPSS 0.2%CVE-2026-52817HIGHLinuxfabrik Monitoring Plugins Sudoers: /usr/bin/apt-get arguments allow privilege escalationEPSS 0.2%CVE-2026-25690MEDIUMAn improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through EPSS 0.2%CVE-2026-18157HIGHYggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution via apt argument injectionEPSS 0.2%CVE-2026-78678HIGHGitPython before 3.1.59 Arbitrary File Read via Repo.blame()EPSS 0.2%CVE-2026-87818HIGHGitPython 3.1.59 Local File Content Oracle via --no-indexEPSS 0.2%CVE-2026-54085HIGHWazuh: Missing input validation in multiple active response scripts allows argument injectionEPSS 0.2%CVE-2026-41013HIGHTenant-controlled comma smuggles arbitrary CIFS mount optionsEPSS 0.2%CVE-2026-23924MEDIUMAgent 2 Docker plugin arbitrary file read via Docker API injectionEPSS 0.2%CVE-2026-74237HIGHGFI Exinda AI / ClearView < 7.6.5 Argument Injection via Tools Iperf ClientEPSS 0.2%CVE-2026-3682MEDIUMwelovemedia FFmate ffmpeg.go Execute argument injectionEPSS 0.2%CVE-2026-40113HIGHPraisonAI has an Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-varsEPSS 0.2%CVE-2026-90467MEDIUMaiosmtplib before 5.1.3 ESMTP Parameter Injection via unvalidated addressesEPSS 0.2%CVE-2023-22632LOWPRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.EPSS 0.2%CVE-2023-22631LOWPRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.EPSS 0.2%CVE-2026-11332HIGHAnsible-core: argument injection in ansible-galaxy role install leads to arbitrary code executionEPSS 0.2%CVE-2026-79685MEDIUMDell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vEPSS 0.2%