Fallos del tipo CWE-306

2611 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2021-47731CRITICALSelea Targa IP Camera Developer Backdoor Configuration OverwriteEPSS 0.5%CVE-2024-48768HIGHAn issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmwaEPSS 0.5%CVE-2026-19875HIGHUnauthenticated Registration POST Endpoint Permits Admin Email Overwrite and Outbound Relay Abuse in LangflowEPSS 0.5%CVE-2025-70147HIGHMissing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackersEPSS 0.5%CVE-2026-73669MEDIUMSignify Philips Hue Bridge Pro MQTT broker missing authenticationEPSS 0.5%CVE-2023-21856HIGHVulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versEPSS 0.5%CVE-2026-34952CRITICALPraisonAI: Missing Authentication in WebSocket GatewayEPSS 0.5%CVE-2025-4557HIGHZONG YU Parking Management System - Missing AuthenticationEPSS 0.5%CVE-2026-19426HIGHFitSoft|POS Sytstem - Missing AuthenticationEPSS 0.5%CVE-2022-24396—The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be aEPSS 0.5%CVE-2018-25335CRITICALWordPress Plugin Peugeot Music 1.0 Arbitrary File UploadEPSS 0.5%CVE-2026-12691HIGHAuthentication Bypass in Vimesoft's Enterprise Video PlatformEPSS 0.5%CVE-2022-31701MEDIUMVMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this isEPSS 0.5%CVE-2025-3232HIGHMitsubishi Electric Europe smartRTU Missing Authentication for Critical FunctionEPSS 0.5%CVE-2024-21272HIGHVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0EPSS 0.5%CVE-2024-47902MEDIUMA vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All veEPSS 0.5%CVE-2023-53969CRITICALScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Password ChangeEPSS 0.5%CVE-2025-5192CRITICALSoar Cloud HRD Human Resource Management System - Missing Authentication for Critical FunctionEPSS 0.5%CVE-2023-53970HIGHScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Reset Board ConfigEPSS 0.5%CVE-2023-53967CRITICALScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Admin Password ChangeEPSS 0.5%