Weaknesses of type CWE-306

2,630 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2025-60251MEDIUMUnitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.EPSS 0.2%CVE-2025-12941MEDIUMDenial of Service Vulnerability in NETGEAR C6220 and C6230EPSS 0.2%CVE-2026-42289HIGHChurchCRM: Cross-Site Request Forgery (CSRF) Leading to Admin Privilege EscalationEPSS 0.2%CVE-2025-9160HIGHRockwell Automation CompactLogix® 5480 Code Execution VulnerabilityEPSS 0.2%CVE-2018-25225HIGHSIPP 3.3 Stack-Based Buffer Overflow via Configuration FileEPSS 0.2%CVE-2024-54013HIGHAuthentication BypassEPSS 0.2%CVE-2023-32460HIGH Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially eEPSS 0.2%CVE-2025-62287MEDIUMVulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server). The supported verEPSS 0.2%CVE-2018-25224HIGHPMS 0.42 Stack-Based Buffer Overflow via Configuration FileEPSS 0.2%CVE-2026-42312MEDIUMpyload-ng: non-admin SETTINGS users can disable outbound TLS peer verificationEPSS 0.2%CVE-2026-12910MEDIUMMissing Authentication for Critical Function in GitLabEPSS 0.2%CVE-2018-25259HIGHTerminal Services Manager 3.1 Buffer Overflow SEHEPSS 0.2%CVE-2020-12491MEDIUMFramework Information Disclosure VulnerabilityEPSS 0.2%CVE-2024-35342MEDIUMCertain Anpviz products allow unauthenticated users to modify or disable camera related settings such as microphone volume, speaker volume, EPSS 0.2%CVE-2021-26264MEDIUMEmerson DeltaV Missing Authentication for Critical FunctionEPSS 0.2%CVE-2025-15481MEDIUMNotification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data DisclosureEPSS 0.2%CVE-2026-55626HIGHxrdp: No authentication required with Xvnc backend on RHEL 9EPSS 0.2%CVE-2026-11838MEDIUMImproper Authorization in Yordam Informatics' Library Reservation SystemEPSS 0.2%CVE-2026-85981MEDIUMUnauthenticated Localhost Admin Panel in Auth0 AD/LDAP ConnectorEPSS 0.2%CVE-2026-25599MEDIUMMissing authentication and clear‑text data transmission affecting Orca heat pumpsEPSS 0.2%