Falhas do tipo CWE-88

311 resultados

Divulgação de Informações

Falha que permite que dados sensíveis (senhas, tokens, chaves, dados pessoais) sejam expostos a usuários ou atacantes que não deveriam ter acesso. O código não implementa controles adequados de acesso ou deixa informações sensíveis visíveis em logs, mensagens de erro, respostas HTTP ou memória.

Exemplo

Um servidor retorna mensagens de erro detalhadas que revelam estrutura do banco de dados, caminhos de arquivos ou nomes de usuários válidos. Ou uma API expõe dados de usuários em resposta JSON sem validar permissões, permitindo qualquer cliente listar informações alheias.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para não expor detalhes internos, revise logs e respostas da API antes de enviar ao cliente, criptografe dados em repouso e em trânsito. Teste regularmente com ferramentas de fuzzing e análise de dados expostos.

CVE-2026-40079HIGHCacti: Command Injection via escape_command() no-op in RRDtool executionEPSS 1.7%CVE-2021-34718HIGHCisco IOS XR Software Arbitrary File Read and Write VulnerabilityEPSS 1.6%CVE-2017-1001003math.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode characters when creatinEPSS 1.5%CVE-2022-45062CRITICALIn Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.EPSS 1.5%CVE-2021-41146HIGHArbitrary command execution on Windows in qutebrowserEPSS 1.5%CVE-2023-50232HIGHInductive Automation Ignition getParams Argument Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-9131HIGHA user with administrator privileges can perform command injectionEPSS 1.4%CVE-2024-20287MEDIUMA vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point SetupEPSS 1.4%CVE-2024-3817CRITICALHashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git BranchesEPSS 1.3%CVE-2025-21613CRITICALgo-git has an Argument Injection via the URL fieldEPSS 1.3%CVE-2023-44452HIGHLinux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2022-31749MEDIUMAuthenticated arbitrary file read/write in WatchGuard Fireware OSEPSS 1.3%CVE-2023-49096HIGHArgument Injection in FFmpeg codec parameters in JellyfinEPSS 1.3%CVE-2021-1484MEDIUMCisco SD-WAN vManage Command Injection VulnerabilityEPSS 1.2%CVE-2026-54501CRITICALBrowsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom BehaviorsEPSS 1.2%CVE-2022-29215HIGHArgument Injection in RegionProtectEPSS 1.2%CVE-2022-42968CRITICALGitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.EPSS 1.2%CVE-2022-23740HIGHImproper Neutralization of Argument Delimiters in a Command in GitHub Enterprise Server leading to Remote Code ExecutionEPSS 1.2%CVE-2023-6792MEDIUMPAN-OS: OS Command Injection Vulnerability in the XML APIEPSS 1.1%CVE-2023-26143MEDIUMVersions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sEPSS 1.1%