Weaknesses of type CWE-88

252 results

Divulgação de Informações

Ocorre quando um programa expõe dados sensíveis (credenciais, tokens, caminhos internos, versões de sistemas) a usuários ou processos não autorizados. O risco está na falta de controle sobre quem acessa o quê, permitindo que informações confidenciais sejam lidas ou inferidas por atacantes.

Example

Um servidor web retorna mensagens de erro detalhadas que revelam a estrutura do banco de dados, ou uma API expõe UUIDs internos de usuários em respostas públicas, ou logs de aplicação contêm senhas armazenadas de forma legível em arquivos acessíveis.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC), sanitize mensagens de erro para produção (sem detalhes técnicos), criptografe dados em repouso e em trânsito, revise permissões de arquivos e endpoints, e monitore o que é expostos em respostas HTTP e logs.

CVE-2016-10033CRITICALThe mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail cEPSS 99.7%KEVCVE-2022-36804HIGHMultiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10,EPSS 99.1%KEVCVE-2026-24061CRITICALtelnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.EPSS 97.9%KEVCVE-2022-23221CRITICALH2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGEPSS 64.8%CVE-2024-52301HIGHLaravel allows environment manipulation via query stringEPSS 44.0%CVE-2024-41710MEDIUMA vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (EPSS 41.6%KEVCVE-2021-1531HIGHCisco Modeling Labs Web UI Command Injection VulnerabilityEPSS 30.5%CVE-2022-37027HIGHAhsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime EPSS 21.7%CVE-2025-57791MEDIUMArgument Injection Vulnerability in CommServeEPSS 21.4%CVE-2024-24576CRITICALRusts's `std::process::Command` did not properly escape arguments of batch files on WindowsEPSS 20.3%CVE-2001-0667HIGHInternet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commandEPSS 14.7%CVE-2026-49373HIGHIn JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settingsEPSS 13.0%CVE-2023-6634HIGHLearnPress <= 4.2.5.7 - Command InjectionEPSS 8.5%CVE-2025-68144MEDIUMmcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local filesEPSS 7.6%CVE-2024-39930CRITICALThe built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. AuthenticEPSS 7.3%CVE-2019-3931Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafteEPSS 5.9%CVE-2021-46850HIGHmyVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and rEPSS 5.4%CVE-2022-26532HIGHA argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEEPSS 4.8%CVE-2021-29472HIGHMissing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial in composerEPSS 4.7%CVE-2022-29184HIGHCommand Injection/Argument Injection in GoCDEPSS 3.7%