Fallos del tipo CWE-306

2599 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2023-46819MEDIUMApache OFBiz: Execution of Solr plugin queries without authenticationEPSS 1.8%CVE-2022-39425HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PriorEPSS 1.8%CVE-2018-4840—A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 EEPSS 1.8%CVE-2019-1876MEDIUMCisco Wide Area Application Services Software HTTPS Proxy Authentication Bypass VulnerabilityEPSS 1.8%CVE-2022-34321HIGHApache Pulsar: Improper Authentication for Pulsar Proxy Statistics EndpointEPSS 1.8%CVE-2020-10282CRITICALRVD#3316: No authentication in MAVLink protocolEPSS 1.8%CVE-2022-34858CRITICALWordPress OAuth 2.0 client for SSO plugin <= 1.11.3 - Authentication Bypass vulnerabilityEPSS 1.8%CVE-2021-34538—Apache Hive Security vulnerability in Hive with UDFsEPSS 1.8%CVE-2014-125126CRITICALSimple E-Document Arbitrary File Upload RCEEPSS 1.7%CVE-2026-75791HIGHAuthentication bypass vulnerabilityEPSS 1.7%CVE-2022-27169HIGHAn information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16EPSS 1.7%CVE-2022-45479CRITICALPC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorizatEPSS 1.7%CVE-2022-45481CRITICALThe default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with noEPSS 1.7%CVE-2020-14501—Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of thEPSS 1.7%CVE-2025-21355HIGHMicrosoft Bing Remote Code Execution VulnerabilityEPSS 1.7%CVE-2024-38143MEDIUMWindows WLAN AutoConfig Service Elevation of Privilege VulnerabilityEPSS 1.7%CVE-2025-34116HIGHIPFire < 2.19 Core Update 101 proxy.cgi RCEEPSS 1.7%CVE-2021-31337—The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow EPSS 1.7%CVE-2026-33340CRITICALLoLLMs WEBUI has unauthenticated Server-Side Request Forgery (SSRF) in /api/proxy endpointEPSS 1.7%CVE-2022-25250HIGHPTC Axeda agent and Axeda Desktop Server Missing Authentication For Critical FunctionEPSS 1.7%