Falhas do tipo CWE-88

311 resultados

Divulgação de Informações

Falha que permite que dados sensíveis (senhas, tokens, chaves, dados pessoais) sejam expostos a usuários ou atacantes que não deveriam ter acesso. O código não implementa controles adequados de acesso ou deixa informações sensíveis visíveis em logs, mensagens de erro, respostas HTTP ou memória.

Exemplo

Um servidor retorna mensagens de erro detalhadas que revelam estrutura do banco de dados, caminhos de arquivos ou nomes de usuários válidos. Ou uma API expõe dados de usuários em resposta JSON sem validar permissões, permitindo qualquer cliente listar informações alheias.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para não expor detalhes internos, revise logs e respostas da API antes de enviar ao cliente, criptografe dados em repouso e em trânsito. Teste regularmente com ferramentas de fuzzing e análise de dados expostos.

CVE-2023-26310HIGHCommand Injection In OPPO ServiceEPSS 1.1%CVE-2024-3684HIGHImproper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management ConsoleEPSS 1.1%CVE-2026-22738CRITICALSpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code ExecutionEPSS 1.1%CVE-2024-23731CRITICALThe OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function arguEPSS 1.1%CVE-2026-86060CRITICALSSH session privilege manipulation via a crafted username in Mikrotik RouterOSEPSS 1.1%KEVCVE-2025-35010HIGHMicrohard Bullet-LTE and IPn4Gii AT+MNPINGTM Argument InjectionEPSS 1.0%CVE-2025-35009HIGHMicrohard Bullet-LTE and IPn4Gii AT+MNNETSP Argument InjectionEPSS 1.0%CVE-2025-35006HIGHMicrohard Bullet-LTE and IPn4Gii AT+MFPORTFWD Argument InjectionEPSS 1.0%CVE-2025-35008HIGHMicrohard Bullet-LTE and IPn4Gii AT+MMNAME Argument InjectionEPSS 1.0%CVE-2025-35005HIGHMicrohard Bullet-LTE and IPn4Gii AT+MFMAC Argument InjectionEPSS 1.0%CVE-2025-35007HIGHMicrohard Bullet-LTE and IPn4Gii AT+MFRULE Argument InjectionEPSS 1.0%CVE-2025-35004HIGHMicrohard Bullet-LTE and IPn4Gii AT+MFIP Argument InjectionEPSS 1.0%CVE-2022-47502Apache OpenOffice: Macro URL arbitrary script executionEPSS 1.0%CVE-2026-57572CRITICALCrawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_argsEPSS 0.9%CVE-2025-3460HIGHON Semiconductor Quantenna set_tx_pow Argument InjectionEPSS 0.9%CVE-2025-48385HIGHGit alllows arbitrary file writes via bundle-uri parameter injectionEPSS 0.9%CVE-2024-35307CRITICALArgument Injection Leading to Remote Code Execution in Realtime Graph ExtensionEPSS 0.9%CVE-2022-1399CRITICALRemote code execution in scheduled tasks componentEPSS 0.9%CVE-2024-47516CRITICALPagure: argument injection in pagurerepo.log()EPSS 0.9%CVE-2026-6951CRITICALVersions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912]EPSS 0.9%