Fallos del tipo CWE-284

7085 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2025-58724HIGHArc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-6443HIGHMikrotik RouterOS VXLAN Source IP Improper Access Control VulnerabilityEPSS 0.6%CVE-2024-0366MEDIUMStarbox – the Author Box for Humans <= 3.4.7 - Insecure Direct Object ReferenceEPSS 0.6%CVE-2021-41834MEDIUMJFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-pEPSS 0.6%CVE-2024-1088MEDIUMPassword Protected Store for WooCommerce <= 2.2 - Information Exposure via REST APIEPSS 0.6%CVE-2022-4807HIGHImproper Access Control in usememos/memosEPSS 0.6%CVE-2024-12478MEDIUMInvoicePlane 1 upload_file unrestricted uploadEPSS 0.6%CVE-2023-40730HIGHA vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks suffiEPSS 0.6%CVE-2025-71380HIGHn8n - Arbitrary Command Execution via Execute Command NodeEPSS 0.6%CVE-2022-3186HIGHDataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the dEPSS 0.6%CVE-2023-0858LOWImproper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on theEPSS 0.6%CVE-2025-12201MEDIUMajayrandhawa User-Management-PHP-MYSQL User Management edit-user.php unrestricted uploadEPSS 0.6%CVE-2023-34106MEDIUMGLPI vulnerable to unauthorized access to User dataEPSS 0.6%CVE-2023-34107MEDIUMGLPI vulnerable to unauthorized access to KnowbaseItem dataEPSS 0.6%CVE-2025-43586HIGHAdobe Commerce | Improper Access Control (CWE-284)EPSS 0.6%CVE-2025-67014HIGHIncorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauthenticated attackers EPSS 0.6%CVE-2025-3585MEDIUMwestboy CicadasCMS JSP Parser upload unrestricted uploadEPSS 0.6%CVE-2024-20657HIGHWindows Group Policy Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-2938MEDIUMSourceCodester Student Result Management System update_smtp.php access controlEPSS 0.6%CVE-2021-28511MEDIUMThis advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches t ...EPSS 0.6%