Falhas do tipo CWE-88

311 resultados

Divulgação de Informações

Falha que permite que dados sensíveis (senhas, tokens, chaves, dados pessoais) sejam expostos a usuários ou atacantes que não deveriam ter acesso. O código não implementa controles adequados de acesso ou deixa informações sensíveis visíveis em logs, mensagens de erro, respostas HTTP ou memória.

Exemplo

Um servidor retorna mensagens de erro detalhadas que revelam estrutura do banco de dados, caminhos de arquivos ou nomes de usuários válidos. Ou uma API expõe dados de usuários em resposta JSON sem validar permissões, permitindo qualquer cliente listar informações alheias.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para não expor detalhes internos, revise logs e respostas da API antes de enviar ao cliente, criptografe dados em repouso e em trânsito. Teste regularmente com ferramentas de fuzzing e análise de dados expostos.

CVE-2026-45068HIGHSymfony: Argument Injection in SendmailTransport via Dash-Prefixed Recipient AddressEPSS 0.5%CVE-2026-0634HIGHCode Execution in AssistFeedbackService on TECNO Pova7 Pro 5GEPSS 0.5%CVE-2024-2422CRITICALLenelS2 NetBox Improper Neutralization of Argumented DelimitersEPSS 0.5%CVE-2026-53790CRITICALrsync < 3.5.0 Command Injection via Multiple Code PathsEPSS 0.5%CVE-2024-52011HIGHlaunch-editor vulnerable to command injection via the crafted request on WindowsEPSS 0.5%CVE-2024-32884MEDIUMgix-transport indirect code execution via malicious usernameEPSS 0.5%CVE-2024-32462HIGHFlatpak vulnerable to a sandbox escape via RequestBackground portal due to bad argument parsingEPSS 0.5%CVE-2026-26194HIGHGogs: Release tag option injection in release deletionEPSS 0.5%CVE-2026-52750HIGHGhidra < 12.1- Command Injection via URL Annotation ClickEPSS 0.5%CVE-2026-44210MEDIUMKata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod AnnotationsEPSS 0.5%CVE-2026-43893HIGHexiftool-vendored: Argument injection via newline characters in tag namesEPSS 0.5%CVE-2023-30577HIGHAMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for runtar.c, a differentEPSS 0.5%CVE-2022-4864MEDIUM Argument Injection in froxlor/froxlorEPSS 0.5%CVE-2026-24126MEDIUMWeblate has an argument injection in management consoleEPSS 0.5%CVE-2025-12556HIGHIDIS ICM Viewer Argument InjectionEPSS 0.5%CVE-2026-44449CRITICALLumiverse: SMB `exists()` basename injection via smbclient `!cmd` escapeEPSS 0.5%CVE-2024-31966MEDIUMA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.4%CVE-2026-54337CRITICALFireshare has Unauthenticated Argument Injection to Arbitrary File Write/OverwriteEPSS 0.4%CVE-2026-76866HIGHNetcore NR255-V 1.5.130703 OS Command Argument Injection via Unquoted DDNS ParametersEPSS 0.4%CVE-2026-16770CRITICALPDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source documentEPSS 0.4%