Fallos del tipo CWE-306

2599 resultados

Ausência de autenticação em funcionalidade crítica

A aplicação permite acesso a operações que exigem identidade verificada ou consomem recursos significativos sem validar quem está fazendo a requisição. Isso permite que qualquer pessoa, autenticada ou não, execute ações sensíveis — desde consumir quotas até acessar dados ou disparar processos custosos.

Ejemplo

Um serviço de relatórios expõe um endpoint `/gerar-relatorio` que processa grandes volumes de dados sem verificar credenciais. Um atacante chama o endpoint repetidas vezes, sobrecarregando a infraestrutura e causando negação de serviço, enquanto qualquer usuário consegue disparar operações com alto custo computacional.

Cómo mitigar

Implemente validação de autenticação (tokens JWT, OAuth, sessões) antes de executar qualquer operação sensível ou de alto custo. Combine com rate limiting e quotas por usuário para restringir abuso mesmo após autenticação.

CVE-2020-10640CRITICALICSA-20-140-02 Emerson OpenEnterpriseEPSS 3.1%CVE-2019-9201CRITICALMultiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make chanEPSS 3.1%CVE-2022-38870HIGHFree5gc v3.2.1 is vulnerable to Information disclosure.EPSS 3.1%CVE-2026-59726CRITICALRuflo: Unauthenticated RCE in MCP bridge default docker-compose deploymentEPSS 3.0%CVE-2022-0424—Popup by Supsystic < 1.10.9 - Unauthenticated Subscriber Email Addresses DisclosureEPSS 3.0%CVE-2025-34113HIGHTiki Wiki CMS Authenticated Command Injection in Calendar ModuleEPSS 3.0%CVE-2025-15517HIGHAuthorization Bypass in HTTP Server Endpoints on TP-Link Archer NX200, NX210, NX500 and NX600EPSS 3.0%CVE-2022-0992CRITICALSiteGround Security <= 1.2.5 - Authentication Bypass via 2FA SetupEPSS 2.9%CVE-2026-59801CRITICAL9Router 0.4.41 - Unauthenticated API Exposure via /api/providersEPSS 2.9%CVE-2020-12500CRITICALPepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx productsEPSS 2.9%CVE-2025-34112CRITICALRiverbed SteelCentral NetProfiler / NetExpress 10.8.7 RCEEPSS 2.9%CVE-2026-9103CRITICALUnauthenticated Superuser Token Issuance via Auto-Login EndpointEPSS 2.8%CVE-2020-10921CRITICALThis vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen EPSS 2.8%CVE-2019-10919—A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Attackers with access to port 10005/tcp couEPSS 2.7%CVE-2019-18339CRITICALA vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVEPSS 2.7%CVE-2018-18995—Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrativEPSS 2.6%CVE-2026-85688CRITICALTEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN DesignerEPSS 2.6%CVE-2019-10922—A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WEPSS 2.6%CVE-2026-30824HIGHFlowise: Missing Authentication on NVIDIA NIM EndpointsEPSS 2.6%CVE-2018-0374—A vulnerability in the Policy Builder database of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to connecEPSS 2.6%