Weaknesses of type CWE-306

2,592 results

Ausência de autenticação em funcionalidades críticas

A aplicação oferece funcionalidades sensíveis ou que consomem recursos significativos (processamento pesado, armazenamento, transações) sem verificar a identidade do usuário. Qualquer pessoa, autenticada ou não, consegue acessar e executar essas operações, comprometendo confidencialidade, integridade e disponibilidade.

Example

Um serviço de geração de relatórios expõe um endpoint `/api/gerar-relatorio` que não valida token JWT ou sessão — um atacante consegue disparar dezenas de requisições simultâneas, sobrecarregando o servidor, ou acessar dados de outros clientes sem se identificar.

How to mitigate

Implemente autenticação obrigatória antes de qualquer operação sensível (valide token, sessão ou credenciais). Para APIs, use OAuth2/JWT com verificação no início da requisição; para aplicações web, enforce sessão válida. Combine com rate limiting e quotas por usuário para conter abuso de recursos.

CVE-2024-3661HIGHDHCP routing options can manipulate interface-based VPN trafficEPSS 4.1%CVE-2018-1164—This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router EPSS 4.0%CVE-2021-42783—Missing Authentication in debug_post_set.cgi in D-Link DWR-932C E1 Firmware 1.0.0.4EPSS 3.9%CVE-2013-10032HIGHGetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File UploadEPSS 3.6%CVE-2026-56782CRITICALGorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore EndpointsEPSS 3.6%CVE-2021-20990HIGHFibaro Home Center Unauthenticated access to shutdown, reboot and reboot to recovery modeEPSS 3.4%CVE-2018-10603—Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commEPSS 3.4%CVE-2026-39363HIGHVite Affected by Arbitrary File Read via Vite Dev Server WebSocketEPSS 3.4%CVE-2026-46339CRITICAL9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routesEPSS 3.4%CVE-2025-34100CRITICALBuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File UploadEPSS 3.3%CVE-2018-4834CRITICALA vulnerability has been identified in Desigo PXC00-E.D V4.10 (All versions < V4.10.111), Desigo PXC00-E.D V5.00 (All versions < V5.0.171), EPSS 3.3%CVE-2025-34115HIGHOP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.phpEPSS 3.3%CVE-2016-6544—iTrack Easy's getgps data can be modified without authenticationEPSS 3.3%CVE-2020-10640CRITICALICSA-20-140-02 Emerson OpenEnterpriseEPSS 3.1%CVE-2019-9201CRITICALMultiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make chanEPSS 3.1%CVE-2022-38870HIGHFree5gc v3.2.1 is vulnerable to Information disclosure.EPSS 3.1%CVE-2022-0424—Popup by Supsystic < 1.10.9 - Unauthenticated Subscriber Email Addresses DisclosureEPSS 3.0%CVE-2025-34113HIGHTiki Wiki CMS Authenticated Command Injection in Calendar ModuleEPSS 3.0%CVE-2025-15517HIGHAuthorization Bypass in HTTP Server Endpoints on TP-Link Archer NX200, NX210, NX500 and NX600EPSS 3.0%CVE-2022-0992CRITICALSiteGround Security <= 1.2.5 - Authentication Bypass via 2FA SetupEPSS 2.9%