Fallos del tipo CWE-306

2636 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2025-30048MEDIUMUnauthenticated access to module configuration endpointEPSS 0.2%CVE-2025-30037HIGHMissing authentication in APIs allowing data retrieval and modificationEPSS 0.2%CVE-2025-44004HIGHUnauthenticated Channel Subscription Creation in Mattermost Confluence PluginEPSS 0.2%CVE-2026-27846MEDIUMMissing authentication in Linksys MR9600, Linksys MX4200EPSS 0.2%CVE-2026-41477HIGHDeskflow: Local privilege escalation via unauthenticated IPCEPSS 0.2%CVE-2025-40816HIGHA vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versionEPSS 0.2%CVE-2021-21535HIGHDell Hybrid Client versions prior to 1.5 contain a missing authentication for a critical function vulnerability. A local unauthenticated attEPSS 0.2%CVE-2025-32063MEDIUMEnabling SSH server on Infotainment ECUEPSS 0.2%CVE-2025-9214MEDIUMA missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or moEPSS 0.2%CVE-2026-19397HIGHMissing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the hosEPSS 0.2%CVE-2026-61742CRITICALDBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL executionEPSS 0.2%CVE-2026-41047MEDIUMInformation leak via “diff” methods in qSnapperEPSS 0.2%CVE-2026-22727HIGHCloud Foundry unprotected internal endpointsEPSS 0.2%CVE-2025-60251MEDIUMUnitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.EPSS 0.2%CVE-2026-42289HIGHChurchCRM: Cross-Site Request Forgery (CSRF) Leading to Admin Privilege EscalationEPSS 0.2%CVE-2025-12941MEDIUMDenial of Service Vulnerability in NETGEAR C6220 and C6230EPSS 0.2%CVE-2025-9160HIGHRockwell Automation CompactLogix® 5480 Code Execution VulnerabilityEPSS 0.2%CVE-2018-25225HIGHSIPP 3.3 Stack-Based Buffer Overflow via Configuration FileEPSS 0.2%CVE-2024-54013HIGHAuthentication BypassEPSS 0.2%CVE-2023-32460HIGH Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially eEPSS 0.2%