Fallos del tipo CWE-284

7074 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2019-10175MEDIUMA flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determEPSS 1.0%CVE-2026-54629HIGHAnyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server ModeEPSS 1.0%CVE-2020-10278MEDIUMRVD#2561: Unprotected BIOS allows user to boot from live OS image.EPSS 1.0%CVE-2025-3783MEDIUMSourceCodester Web-based Pharmacy Product Management System add-product.php unrestricted uploadEPSS 1.0%CVE-2025-46628HIGHLack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attackeEPSS 1.0%CVE-2026-2056MEDIUMD-Link DIR-605L/DIR-619L DHCP Connection Status wan_connection_status.asp information disclosureEPSS 1.0%CVE-2026-2055MEDIUMD-Link DIR-605L/DIR-619L DHCP Client Information information disclosureEPSS 1.0%CVE-2023-44794—An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.EPSS 1.0%CVE-2026-2054MEDIUMD-Link DIR-605L/DIR-619L Wifi Setting information disclosureEPSS 1.0%CVE-2023-38945HIGHMultilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.0EPSS 1.0%CVE-2025-48817HIGHRemote Desktop Client Remote Code Execution VulnerabilityEPSS 1.0%CVE-2022-22190HIGHParagon Active Assurance Control Center: Information disclosure vulnerability in crafted URLEPSS 1.0%CVE-2022-24731MEDIUMPath traversal allows leaking out-of-bound files from Argo CD repo-serverEPSS 1.0%CVE-2024-23315HIGHA read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of AutomationDirect P3-550EEPSS 1.0%CVE-2024-40786HIGHThis issue was addressed through improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, mEPSS 1.0%CVE-2018-16466—Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acEPSS 1.0%CVE-2023-23923—Moodle: possible to set the preferred "start page" of other usersEPSS 1.0%CVE-2023-22250MEDIUMAdobe Commerce Improper Access Control Security feature bypassEPSS 1.0%CVE-2022-26317—A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29). When returning the result of a completeEPSS 1.0%CVE-2023-36644HIGHIncorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the EPSS 1.0%