Falhas do tipo CWE-88

311 resultados

Divulgação de Informações

Falha que permite que dados sensíveis (senhas, tokens, chaves, dados pessoais) sejam expostos a usuários ou atacantes que não deveriam ter acesso. O código não implementa controles adequados de acesso ou deixa informações sensíveis visíveis em logs, mensagens de erro, respostas HTTP ou memória.

Exemplo

Um servidor retorna mensagens de erro detalhadas que revelam estrutura do banco de dados, caminhos de arquivos ou nomes de usuários válidos. Ou uma API expõe dados de usuários em resposta JSON sem validar permissões, permitindo qualquer cliente listar informações alheias.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para não expor detalhes internos, revise logs e respostas da API antes de enviar ao cliente, criptografe dados em repouso e em trânsito. Teste regularmente com ferramentas de fuzzing e análise de dados expostos.

CVE-2026-32304CRITICALLocutus: RCE via unsanitized input in create_function()EPSS 0.6%CVE-2025-32931CRITICALDevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands vEPSS 0.6%CVE-2025-0065HIGHImproper Neutralization of Argument Delimiters in TeamViewer ClientsEPSS 0.6%CVE-2026-31230CRITICALThe Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robEPSS 0.6%CVE-2026-46483LOWVim: Command injection in tar#Vimuntar via missing shellescape {special} flagEPSS 0.6%CVE-2024-41711MEDIUMA vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (EPSS 0.5%CVE-2026-12856HIGHVscode-java: vscode: command injection vulnerability in the javadoc hover provider of the vscode-java extensionEPSS 0.5%CVE-2025-59937HIGHgo-mail has insufficient address encoding when passing mail addresses to the SMTP clientEPSS 0.5%CVE-2026-73240CRITICALApache Allura: Git command injectionEPSS 0.5%CVE-2026-49987HIGHRepomix: Command Injection (RCE) via `--remote-branch` Argument InjectionEPSS 0.5%CVE-2025-46835HIGHGit GUI can create and overwrite files for which the user has write permissionEPSS 0.5%CVE-2026-44189HIGHAnsible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execution via malicious playbook filenameEPSS 0.5%CVE-2026-25689MEDIUMAn improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.2.0, FortiDeEPSS 0.5%CVE-2022-44731MEDIUMA vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions < V3.15 P038), SIMATIC WinCC OA V3.16 (All versions < V3.16 P035EPSS 0.5%CVE-2026-45158CRITICALOPNsense: Command Injection via Attacker-Controlled DHCP ConfigEPSS 0.5%CVE-2026-44790CRITICALn8n: Arbitrary File Read via Git NodeEPSS 0.5%CVE-2022-37005HIGHThe Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentialEPSS 0.5%CVE-2019-5012HIGHAn exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the startProcess coEPSS 0.5%CVE-2026-46529HIGHPDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenEPSS 0.5%CVE-2026-6437MEDIUMAWS EFS CSI Driver Mount Option InjectionEPSS 0.5%