Fallos del tipo CWE-306

2599 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2021-32930—The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and eEPSS 8.1%CVE-2025-52089HIGHA hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to exEPSS 8.0%CVE-2024-21006HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 7.9%CVE-2025-59246CRITICALAzure Entra ID Elevation of Privilege VulnerabilityEPSS 7.7%CVE-2023-7308HIGHSecGate3600 Firewall Information Disclosure via authManageSet.cgiEPSS 7.5%CVE-2015-10141CRITICALXdebug Remote Debugger Unauthenticated OS Command ExecutionEPSS 7.4%CVE-2023-37265CRITICALIncorrect identification of source IP addresses in CasaOSEPSS 7.4%CVE-2025-24865CRITICALmySCADA myPRO Manager Missing Authentication for Critical FunctionEPSS 7.2%CVE-2025-55583CRITICALD-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi EPSS 7.0%CVE-2024-32735CRITICALCyberPower PowerPanel Enterprise Missing AuthenticationEPSS 6.8%CVE-2026-62241CRITICALclawvet < 0.7.5 Hard-coded JWT Secret Session ForgeryEPSS 6.5%CVE-2025-52692HIGHBypass AuthenticationEPSS 6.4%CVE-2022-46463HIGHAn access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. EPSS 6.2%CVE-2024-57725MEDIUMAn issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication,EPSS 6.2%CVE-2025-34103CRITICALWePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgiEPSS 6.0%CVE-2024-5721HIGHLogsign Unified SecOps Platform Missing Authentication Remote Code Execution VulnerabilityEPSS 6.0%CVE-2017-3184—ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory EPSS 5.9%CVE-2024-21306MEDIUMMicrosoft Bluetooth Driver Spoofing VulnerabilityEPSS 5.8%CVE-2023-54335CRITICALeXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)EPSS 5.8%CVE-2025-14346CRITICALWHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within ranEPSS 5.6%