Falhas do tipo CWE-88

311 resultados

Divulgação de Informações

Falha que permite que dados sensíveis (senhas, tokens, chaves, dados pessoais) sejam expostos a usuários ou atacantes que não deveriam ter acesso. O código não implementa controles adequados de acesso ou deixa informações sensíveis visíveis em logs, mensagens de erro, respostas HTTP ou memória.

Exemplo

Um servidor retorna mensagens de erro detalhadas que revelam estrutura do banco de dados, caminhos de arquivos ou nomes de usuários válidos. Ou uma API expõe dados de usuários em resposta JSON sem validar permissões, permitindo qualquer cliente listar informações alheias.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para não expor detalhes internos, revise logs e respostas da API antes de enviar ao cliente, criptografe dados em repouso e em trânsito. Teste regularmente com ferramentas de fuzzing e análise de dados expostos.

CVE-2026-40281CRITICALGotenberg vulnerable to argument injection via newlines in ExifTool metadata valuesEPSS 0.6%CVE-2025-32458HIGHON Semiconductor Quantenna router_command.sh (in the get_syslog_from_qtn argument) Argument InjectionEPSS 0.6%CVE-2025-32457HIGHON Semiconductor Quantenna router_command.sh (in the get_file_from_qtn argument) Argument InjectionEPSS 0.6%CVE-2020-3380HIGHCisco Data Center Network Manager Privilege Escalation VulnerabilityEPSS 0.6%CVE-2025-32456HIGHON Semiconductor Quantenna router_command.sh (in the put_file_to_qtn argument) Argument InjectionEPSS 0.6%CVE-2019-5013HIGHAn exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the start/stopLauncEPSS 0.6%CVE-2025-3459HIGHON Semiconductor Quantenna transmit_file Argument InjectionEPSS 0.6%CVE-2024-21533MEDIUMAll versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specifying the remote URL EPSS 0.6%CVE-2025-32459HIGHON Semiconductor Quantenna router_command.sh (in the sync_time argument) Argument InjectionEPSS 0.6%CVE-2025-32455HIGHON Semiconductor Quantenna router_command.sh (in the run_cmd argument) Argument InjectionEPSS 0.6%CVE-2025-49008CRITICALAtheos Improper Input Validation Vulnerability Enables RCE in Common.phpEPSS 0.6%CVE-2025-59489HIGHUnity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code fEPSS 0.6%CVE-2021-21384MEDIUMNull characters not escaped in shescapeEPSS 0.6%CVE-2026-42284HIGHGitPython: Unsafe option check validates multi_options before shlex.split transforms itEPSS 0.6%CVE-2026-76220HIGHGitPython before 3.1.58 Command Execution via split_single_char_optionsEPSS 0.6%CVE-2026-73294CRITICALSemaphore U: OS Command InjectionEPSS 0.6%CVE-2022-46883HIGHMozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in FirEPSS 0.6%CVE-2025-49520HIGHEvent-driven-ansible: authenticated argument injection in git url in eda project creationEPSS 0.6%CVE-2025-61731HIGHArbitrary file write using cgo pkg-config directive in cmd/goEPSS 0.6%CVE-2026-65770CRITICALAzure Managed Instance for Apache Cassandra Remote Code Execution VulnerabilityEPSS 0.6%