Fallos del tipo CWE-306

2599 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2020-6287CRITICALSAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows anEPSS 94.7%KEVCVE-2025-4008HIGHArbitrary Command Injection in Smartbedded MeteoBridgeEPSS 93.7%KEVCVE-2023-36846MEDIUMJunos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesEPSS 93.5%KEVCVE-2021-44077CRITICALZoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unEPSS 93.3%KEVCVE-2024-5910CRITICALExpedition: Missing Authentication Leads to Admin Account TakeoverEPSS 91.8%KEVCVE-2024-11680CRITICALProjectSend Unauthenticated Configuration ModificationEPSS 91.7%KEVCVE-2020-3952CRITICALUnder certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)EPSS 90.4%KEVCVE-2025-61757CRITICALVulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affectEPSS 88.6%KEVCVE-2026-24423CRITICALSmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub APIEPSS 88.2%KEVCVE-2022-26143CRITICALThe TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers toEPSS 87.3%KEVCVE-2024-51567CRITICALupgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication andEPSS 86.6%KEVCVE-2021-45232—security vulnerability on unauthorized access.EPSS 86.3%CVE-2023-36847MEDIUMJunos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesEPSS 85.4%KEVCVE-2022-24990CRITICALTerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/aEPSS 83.6%KEVCVE-2021-25094—Tatsu < 3.3.12 - Unauthenticated RCEEPSS 83.4%CVE-2023-21931HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 82.3%CVE-2021-33543CRITICALUDP Technology/Geutebrück camera devices: Authentication BypassEPSS 81.3%CVE-2014-9195—Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical FunctionEPSS 80.7%CVE-2021-1499MEDIUMCisco HyperFlex HX Data Platform File Upload VulnerabilityEPSS 80.4%CVE-2023-27532HIGHVulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. ThisEPSS 77.6%KEV