Weaknesses of type CWE-306

2,629 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-23293HIGHNVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized actioEPSS 0.2%CVE-2024-31684LOWIncorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows attackers to bypass fEPSS 0.2%CVE-2024-47555HIGHMissing Authentication - User & System ConfigurationEPSS 0.2%CVE-2023-47232MEDIUMWordPress WP Affiliate Disclosure plugin <= 1.2.6 - Broken Access Control + CSRF vulnerabilityEPSS 0.2%CVE-2026-78306HIGHDJI Drone Bluetooth Interface Unauthenticated DUML Command ExecutionEPSS 0.2%CVE-2025-64056MEDIUMFile upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the fiEPSS 0.2%CVE-2023-0463HIGHThe force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022EPSS 0.2%CVE-2020-12484MEDIUMWhen using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprisEPSS 0.2%CVE-2026-48106HIGHArc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peerEPSS 0.2%CVE-2026-57112HIGHPraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered toolsEPSS 0.2%CVE-2025-3646MEDIUMPetlibro Smart Pet Feeder Platform through 1.7.31 Authorization Bypass via Device Share APIEPSS 0.2%CVE-2025-13870LOWUnauthorized access and subscription vulnerability in BoardsEPSS 0.2%CVE-2026-85478LOWCareCam CM2507 Missing Authentication for Critical FunctionEPSS 0.2%CVE-2025-3758HIGHExposure of Device Configuration without Authentication in WF2220EPSS 0.2%CVE-2025-11130HIGHiHongRen pptp-vpn XPC Service HelperTool.m shouldAcceptNewConnection missing authenticationEPSS 0.2%CVE-2025-40817HIGHA vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versionEPSS 0.2%CVE-2026-84696CRITICALPhison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique CommandsEPSS 0.2%CVE-2025-47870MEDIUMTeam invite ID leaked to team admin with no member invite privilegesEPSS 0.2%CVE-2024-39364HIGHAdvantech ADAM-5630 Missing Authentication for Critical FunctionEPSS 0.2%CVE-2026-10054HIGHIn affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shellEPSS 0.2%