Falhas do tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou enforçar corretamente quem pode acessar quais recursos ou funcionalidades. Isso permite que usuários não autorizados executem ações, visualizem dados sensíveis ou acessem áreas administrativas que deveriam estar restritas.

Exemplo

Um sistema bancário que valida se o usuário está logado, mas não verifica se ele tem permissão para acessar a conta de outro cliente — bastaria mudar o ID na URL (ex: `/conta/123` para `/conta/456`) para ver dados alheios.

Como mitigar

Implemente verificações de autorização em todas as operações sensíveis, não confie apenas em obscuridade de URLs ou IDs. Use listas de controle de acesso (ACL) ou papéis (RBAC) centralizados, e valide permissões no servidor antes de retornar qualquer dado ou executar ação.

CVE-2026-25573HIGHA vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell commands with caller-pEPSS 0.4%CVE-2025-62611HIGHaiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL serverEPSS 0.4%CVE-2026-19009MEDIUMTinyAGI Message API Endpoint response.ts collectFiles file inclusionEPSS 0.4%CVE-2025-12656LOWMigration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory DeletionEPSS 0.4%CVE-2026-26359HIGHDell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker wEPSS 0.4%CVE-2026-33949HIGH@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary filesEPSS 0.4%CVE-2025-48783HIGHSoar Cloud HRD Human Resource Management System - External Control of File Name or PathEPSS 0.4%CVE-2026-8118MEDIUMRoyal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File SourceEPSS 0.4%CVE-2025-6237CRITICALPath Traversal and Arbitrary File Deletion in invoke-ai/invokeaiEPSS 0.4%CVE-2025-66257CRITICALUnauthenticated Arbitrary File Deletion (patch_contents.php)EPSS 0.4%CVE-2025-66254HIGHUnauthenticated Arbitrary File Deletion (upgrade_contents.php)EPSS 0.4%CVE-2026-24708HIGHAn issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a rooEPSS 0.4%CVE-2022-4983MEDIUMTEC-IT TBarCode SDK 11.15 Remote File CreateEPSS 0.4%CVE-2026-48798HIGHSSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP FilenamesEPSS 0.4%CVE-2020-36772MEDIUMCloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to reEPSS 0.4%CVE-2026-9587HIGHAuthenticated Local File Inclusion (LFI) in Switchvox SMB Web PortalEPSS 0.4%CVE-2011-10030HIGHFoxit PDF Reader < 4.3.1.0218 JavaScript File WriteEPSS 0.4%CVE-2026-15736HIGHMultiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowflake-sqlalchemyEPSS 0.4%CVE-2025-29930MEDIUMimFAQ allows local file inclusion in seo.phpEPSS 0.4%CVE-2025-59511HIGHWindows WLAN Service Elevation of Privilege VulnerabilityEPSS 0.4%