Falhas do tipo CWE-88

311 resultados

Divulgação de Informações

Falha que permite que dados sensíveis (senhas, tokens, chaves, dados pessoais) sejam expostos a usuários ou atacantes que não deveriam ter acesso. O código não implementa controles adequados de acesso ou deixa informações sensíveis visíveis em logs, mensagens de erro, respostas HTTP ou memória.

Exemplo

Um servidor retorna mensagens de erro detalhadas que revelam estrutura do banco de dados, caminhos de arquivos ou nomes de usuários válidos. Ou uma API expõe dados de usuários em resposta JSON sem validar permissões, permitindo qualquer cliente listar informações alheias.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para não expor detalhes internos, revise logs e respostas da API antes de enviar ao cliente, criptografe dados em repouso e em trânsito. Teste regularmente com ferramentas de fuzzing e análise de dados expostos.

CVE-2025-6232HIGHAn improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute coEPSS 0.2%CVE-2025-67858HIGHA crafted "interface" input parameter can lead to integrity loss of the firewall configurationEPSS 0.2%CVE-2026-11968MEDIUMImproper Neutralization of Argument Delimiters in a Command ('Argument Injection') in TortoiseGitEPSS 0.2%CVE-2026-64624HIGHFreeRDP RDP File Parser Remote Code Execution via CLI OptionsEPSS 0.2%CVE-2026-16493HIGHAnsible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for cve-2026-11332)EPSS 0.2%CVE-2026-81529HIGHConnection-option injection via unescaped settings in the canonical MongoDB URL builderEPSS 0.2%CVE-2026-68939LOWPyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)EPSS 0.2%CVE-2026-43943HIGHelecterm: RCE via malicious SSH server filename in openFileWithEditorEPSS 0.2%CVE-2026-68766HIGHhashcat through 7.1.2 Arbitrary File Write via Restore File Option InjectionEPSS 0.2%CVE-2025-41761HIGHPrivilege escalation possibleEPSS 0.2%CVE-2026-94588MEDIUMIn Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper EPSS 0.2%CVE-2026-45181MEDIUMHex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers EPSS 0.2%CVE-2026-89066HIGHOS command injection in the task synthesis component in projenEPSS 0.2%CVE-2026-78635MEDIUMImproper Input Validation in the Okta Privileged Access SSH Client URL Handler ArgumentEPSS 0.2%CVE-2026-44712HIGHpam_usb: Shell injection via device UUID and username in pamusb-conf and pamusb-agentEPSS 0.2%CVE-2025-66002MEDIUMLocal users can perform arbitrary unmounts via smb4k mount helper due to lack of input validationEPSS 0.2%CVE-2026-80427HIGHbestzip before 2.2.6 and 3.0.x before 3.0.2 Argument Injection via Missing Option DelimiterEPSS 0.2%CVE-2026-93337HIGHNetworkManager-l2tp Privilege Escalation via pppd Plugin InjectionEPSS 0.1%CVE-2026-90894HIGHParallels Desktop local privilege escalation via appliance extract argument injectionEPSS 0.1%CVE-2026-1716MEDIUMAn input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow aEPSS 0.1%