Weaknesses of type CWE-306

2,592 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2020-6287CRITICALSAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows anEPSS 94.7%KEVCVE-2025-4008HIGHArbitrary Command Injection in Smartbedded MeteoBridgeEPSS 93.7%KEVCVE-2023-36846MEDIUMJunos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesEPSS 93.5%KEVCVE-2021-44077CRITICALZoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unEPSS 93.3%KEVCVE-2024-5910CRITICALExpedition: Missing Authentication Leads to Admin Account TakeoverEPSS 91.8%KEVCVE-2024-11680CRITICALProjectSend Unauthenticated Configuration ModificationEPSS 91.7%KEVCVE-2020-3952CRITICALUnder certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)EPSS 90.4%KEVCVE-2025-61757CRITICALVulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affectEPSS 88.6%KEVCVE-2026-24423CRITICALSmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub APIEPSS 88.2%KEVCVE-2022-26143CRITICALThe TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers toEPSS 87.3%KEVCVE-2024-51567CRITICALupgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication andEPSS 86.6%KEVCVE-2021-45232—security vulnerability on unauthorized access.EPSS 86.3%CVE-2023-36847MEDIUMJunos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesEPSS 85.4%KEVCVE-2022-24990CRITICALTerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/aEPSS 83.6%KEVCVE-2021-25094—Tatsu < 3.3.12 - Unauthenticated RCEEPSS 83.4%CVE-2023-21931HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 82.3%CVE-2021-33543CRITICALUDP Technology/Geutebrück camera devices: Authentication BypassEPSS 81.3%CVE-2014-9195—Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical FunctionEPSS 80.7%CVE-2021-1499MEDIUMCisco HyperFlex HX Data Platform File Upload VulnerabilityEPSS 80.4%CVE-2023-27532HIGHVulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. ThisEPSS 77.6%KEV