Fallos del tipo CWE-306

2610 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2024-41793HIGHA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an enEPSS 0.5%CVE-2019-25227HIGHTellion HN-2204AP Unauthenticated Configuration DisclosureEPSS 0.5%CVE-2025-11529MEDIUMChurchCRM API Endpoint AuthMiddleware.php AuthMiddleware missing authenticationEPSS 0.5%CVE-2025-45814CRITICALMissing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attacEPSS 0.5%CVE-2025-30727CRITICALVulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected EPSS 0.5%CVE-2024-48882HIGHA denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network pEPSS 0.5%CVE-2023-37373MEDIUMA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications accept unauthenticated file writeEPSS 0.5%CVE-2025-23417HIGHA denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted EPSS 0.5%CVE-2026-33951MEDIUMsignalk-server: Unauthenticated Source Priorities ManipulationEPSS 0.5%CVE-2024-56799CRITICALSimofa Allows Unauthenticated Access to API RoutesEPSS 0.5%CVE-2026-31240HIGHThe mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as upEPSS 0.5%CVE-2025-62582CRITICALDIAView - Authentication Bypass VulnerabilityEPSS 0.5%CVE-2025-7328CRITICALRockwell Automation Comms - 1783-NATR Multiple Broken Authentication VulnerabilitiesEPSS 0.5%CVE-2024-12869MEDIUMImproper Authentication in infiniflow/ragflowEPSS 0.5%CVE-2026-56286HIGHCapgo - Account Deletion Without Password ConfirmationEPSS 0.5%CVE-2026-44328HIGHfree5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutatingEPSS 0.5%CVE-2024-50381HIGHMissing Authentication for Critical Function in Snap One OVRC cloudEPSS 0.5%CVE-2026-14952HIGHFrauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is offering files with sensitive information for download without requiring authenticationEPSS 0.5%CVE-2026-41899MEDIUMCoolify unauthenticated feedback endpoint allows Discord webhook abuseEPSS 0.5%CVE-2026-67578HIGHFA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the EPSS 0.5%