Weaknesses of type CWE-73

668 results

Controle de acesso impróprio

Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.

Example

Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.

How to mitigate

Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.

CVE-2023-0003MEDIUMCortex XSOAR: Local File Disclosure Vulnerability in the Cortex XSOAR ServerEPSS 1.3%CVE-2023-49738HIGHAn information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A speciallyEPSS 1.3%CVE-2025-24996MEDIUMNTLM Hash Disclosure Spoofing VulnerabilityEPSS 1.3%CVE-2024-27943HIGHA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload geneEPSS 1.3%CVE-2024-43615HIGHMicrosoft OpenSSH for Windows Remote Code Execution VulnerabilityEPSS 1.2%CVE-2021-3845External Control of File Name or Path in netristv/ws-scrcpyEPSS 1.2%CVE-2025-26646HIGH.NET, Visual Studio, and Build Tools for Visual Studio Spoofing VulnerabilityEPSS 1.2%CVE-2020-5297LOWUpload whitelisted files to any directory in OctoberCMSEPSS 1.2%CVE-2022-2638Export All URLs < 4.4 - Admin+ Arbitrary System File RemovalEPSS 1.2%CVE-2026-29962HIGHHSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The eEPSS 1.2%CVE-2023-2152MEDIUMSourceCodester Student Study Center Desk Management System index.php file inclusionEPSS 1.2%CVE-2025-71338CRITICALFlowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-store APIEPSS 1.2%CVE-2022-2400MEDIUMExternal Control of File Name or Path in dompdf/dompdfEPSS 1.2%CVE-2021-38477CRITICALAUVESY VersiondogEPSS 1.2%CVE-2020-9752Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through iEPSS 1.1%CVE-2025-59185MEDIUMNTLM Hash Disclosure Spoofing VulnerabilityEPSS 1.1%CVE-2024-12058MEDIUMExternal control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a rEPSS 1.1%CVE-2023-35308MEDIUMWindows MSHTML Platform Security Feature Bypass VulnerabilityEPSS 1.1%CVE-2018-19945Improper Limitation of a Pathname to a Restricted Directory in QTSEPSS 1.1%CVE-2026-54108MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 1.1%