Fallos del tipo CWE-284

7070 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2024-38202HIGHWindows Update Stack Elevation of Privilege VulnerabilityEPSS 1.7%CVE-2019-10962—BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway WEPSS 1.7%CVE-2018-15459MEDIUMCisco Identity Services Engine Privilege Escalation VulnerabilityEPSS 1.7%CVE-2022-37393—Zimbra zmslapd arbitrary module loadEPSS 1.7%CVE-2019-6520—Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuEPSS 1.7%CVE-2019-3567—In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder EPSS 1.7%CVE-2025-33056HIGHWindows Local Security Authority (LSA) Denial of Service VulnerabilityEPSS 1.7%CVE-2022-39399LOWVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versionsEPSS 1.6%CVE-2025-4751MEDIUMD-Link DI-7003GV2 index.data information disclosureEPSS 1.6%CVE-2020-9668HIGHAGSService program mishandling symbolic linksEPSS 1.6%CVE-2025-24989HIGHMicrosoft Power Pages Elevation of Privilege VulnerabilityEPSS 1.6%KEVCVE-2021-24583—Timetable and Event Schedule by MotoPress < 2.4.2 - Unauthorised Event TimeSlot DeletionEPSS 1.6%CVE-2024-49068HIGHMicrosoft SharePoint Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2026-21627CRITICALExtension - tassos.gr - SQL injection and Unauthenticated File Read in Novarain/Tassos Framework v4.10.14 – v6.0.37 for JoomlaEPSS 1.6%CVE-2014-2365—Advantech WebAccess Improper Access ControlEPSS 1.6%CVE-2019-1686MEDIUMCisco ASR 9000 Series Aggregation Services Routers ACL Bypass VulnerabilityEPSS 1.6%CVE-2026-24302HIGHAzure Arc Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2022-34259MEDIUMAdobe Commerce Improper Access Control Security feature bypassEPSS 1.6%CVE-2026-16330MEDIUMD-Link DNS-320 uploadify.php unrestricted uploadEPSS 1.6%CVE-2026-16327MEDIUMD-Link DNS-320 upload.php unrestricted uploadEPSS 1.6%