Fallos del tipo CWE-287

2400 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-22278MEDIUMm-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenticated attacker to byEPSS 0.7%CVE-2025-54376HIGHHoverfly's WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled.EPSS 0.7%CVE-2022-39246HIGHmatrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessionsEPSS 0.7%CVE-2026-25893CRITICALFUXA Unauthenticated Remote Code Execution via Admin JWT MintingEPSS 0.7%CVE-2020-18305HIGHExtreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, EPSS 0.7%CVE-2023-51484CRITICALWordPress Login as User or Customer plugin <= 3.8 - Unauthenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2025-15455MEDIUMbg5sbk MiniCMS File Recovery Request page.php delete_page improper authenticationEPSS 0.7%CVE-2025-0070CRITICALImproper Authentication in SAP NetWeaver ABAP Server and ABAP PlatformEPSS 0.7%CVE-2023-41956HIGHWordPress Simple Membership plugin <= 4.3.4 - Authenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2025-26685MEDIUMMicrosoft Defender for Identity Spoofing VulnerabilityEPSS 0.7%CVE-2026-8508MEDIUMAn improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 couEPSS 0.7%CVE-2023-0105MEDIUMA flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An EPSS 0.7%CVE-2021-32646MEDIUMEscalation of permissions in roomerEPSS 0.7%CVE-2024-2112MEDIUMForm Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information ExposureEPSS 0.7%CVE-2023-7079MEDIUMArbitrary remote file read in Wrangler dev serverEPSS 0.7%CVE-2025-45777CRITICALAn issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supEPSS 0.7%CVE-2023-51478CRITICALWordPress Build App Online plugin <= 1.0.19 - Unauthenticated Account Takeover vulnerabilityEPSS 0.7%CVE-2022-0910MEDIUMA downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmwareEPSS 0.7%CVE-2024-1147CRITICALWeak Access Control - Arbitrary file downloadEPSS 0.7%CVE-2024-1148CRITICALWeak Access Control - Arbitrary file uploadEPSS 0.7%