Fallos del tipo CWE-287

2420 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2025-7574CRITICALLB-LINK BL-WR9000 Web Interface lighttpd.cgi restore improper authenticationEPSS 0.8%CVE-2024-10963HIGHPam: improper hostname interpretation in pam_access leads to access control bypassEPSS 0.8%CVE-2022-31131MEDIUMOwnership check missing when updating or deleting mail attachments in Nextcloud mailEPSS 0.8%CVE-2022-22289MEDIUMImproper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.EPSS 0.8%CVE-2024-25313HIGHCode-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_logEPSS 0.8%CVE-2022-21692MEDIUMImproper Access Control in OnionshareEPSS 0.8%CVE-2024-1817HIGHDemososo DM Enterprise Website Building System Cookie indexDM_load.php dmlogin improper authenticationEPSS 0.8%CVE-2022-39267HIGHBrokercap Bifrost vulnerable to authentication bypass for admin and monitor user groupsEPSS 0.8%CVE-2021-3424A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can registeEPSS 0.8%CVE-2025-3268MEDIUMqinguoyi TinyWebServer http_conn.cpp improper authenticationEPSS 0.8%CVE-2025-5512MEDIUMquequnlong shiyi-blog Administrator Backend verifyPassword improper authenticationEPSS 0.8%CVE-2022-23505MEDIUMPassport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authenticationEPSS 0.8%CVE-2024-7012CRITICALPuppet-foreman: an authentication bypass vulnerability exists in foremanEPSS 0.8%CVE-2025-14567MEDIUMhaxxorsid Stock-Management-System employees missing authenticationEPSS 0.8%CVE-2023-5329MEDIUMField Logic DataCube4 Web API improper authenticationEPSS 0.8%CVE-2026-32174HIGHAzure Bot Service Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2019-15620Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another sharedEPSS 0.8%CVE-2024-13111MEDIUMBeijing Yunfan Internet Technology Yunfan Learning Examination System JWT Token SysUserControl improper authenticationEPSS 0.8%CVE-2018-17928The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing thEPSS 0.8%CVE-2024-7401HIGHClient Enrollment Process BypassEPSS 0.8%