Fallos del tipo CWE-306

2632 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2025-3498CRITICALUnauthenticated modification of Radiflow iSAP Smart Collector configurationEPSS 0.3%CVE-2025-61756HIGHVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.3%CVE-2025-56405HIGHAn issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP serviceEPSS 0.3%CVE-2026-88410HIGHThe graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the EPSS 0.3%CVE-2025-54849HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A speEPSS 0.3%CVE-2025-54850HIGHA denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A speEPSS 0.3%CVE-2025-12049CRITICALMissing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may EPSS 0.3%CVE-2025-62619MEDIUMMissing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the exposed URL to retrievEPSS 0.3%CVE-2026-0942MEDIUMRede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.5 - Missing Authorization to Unauthenticated Rede Order Logs DeletionEPSS 0.3%CVE-2019-25568CRITICALMemu Play 6.0.7 Privilege Escalation via Insecure File PermissionsEPSS 0.3%CVE-2026-100192MEDIUMX-SpringBoot through 6.0 Credential Exposure via Unauthenticated EndpointEPSS 0.3%CVE-2026-73222HIGHClaude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)EPSS 0.3%CVE-2018-19636HIGHLocal root exploit via inclusion of attacker controlled shell scriptEPSS 0.3%CVE-2024-34268HIGHEQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth EPSS 0.3%CVE-2025-8627HIGHUnauthenticated Protocol Commands on TP-Link KP303EPSS 0.3%CVE-2023-46096MEDIUMA vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly authentEPSS 0.3%CVE-2025-11771MEDIUMCryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.7 - Missing Authentication to Unauthenticated Presale UpdateEPSS 0.3%CVE-2025-6226MEDIUMIDOR in CreatePost API allows for timeboxed message disclosureEPSS 0.3%CVE-2025-60856MEDIUMReolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical accEPSS 0.3%CVE-2026-71203MEDIUMchangedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI SchemaEPSS 0.3%