Fallos del tipo CWE-284

7123 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2023-39731—The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast meEPSS 0.4%CVE-2023-42179CRITICALBird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation procEPSS 0.4%CVE-2025-60784MEDIUMA vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.EPSS 0.4%CVE-2024-10937MEDIUMRelated Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.58 - Sensitive Information ExposureEPSS 0.4%CVE-2026-55548MEDIUMYamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packetsEPSS 0.4%CVE-2025-14199MEDIUMVerysync 微力同步 Web Administration text.txt unrestricted uploadEPSS 0.4%CVE-2020-12024—Baxter ExactaMix EM 2400 versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 does not restrict access to theEPSS 0.4%CVE-2026-67975HIGHIncorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TEPSS 0.4%CVE-2026-0577MEDIUMcode-projects Online Product Reservation System prod.php unrestricted uploadEPSS 0.4%CVE-2026-0547MEDIUMPHPGurukul Online Course Registration Student Registration edit-student-profile.php unrestricted uploadEPSS 0.4%CVE-2025-20153MEDIUMCisco ESA mail BypassEPSS 0.4%CVE-2024-28805CRITICALAn issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.EPSS 0.4%CVE-2023-33155HIGHWindows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-52537HIGHVulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will afEPSS 0.4%CVE-2023-47858MEDIUMDetails of archived public channels are leaked to members of another teamEPSS 0.4%CVE-2025-57247CRITICALThe BATBToken smart contract (address 0xfbf1388408670c02f0dbbb74251d8ded1d63b7a2, Compiler Version v0.8.26+commit.8a97fa7a) contains incorreEPSS 0.4%CVE-2025-10371MEDIUMeCharge Hardy Barth Salia PLCC api.php unrestricted uploadEPSS 0.4%CVE-2025-29421HIGHPerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.EPSS 0.4%CVE-2026-2851MEDIUMyeqifu warehouse Inport Endpoint InportController.java deleteInport access controlEPSS 0.4%CVE-2024-51988MEDIUMHTTP API's queue deletion endpoint does not verify that the user has a required permissionEPSS 0.4%