Falhas do tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou enforçar corretamente quem pode acessar quais recursos ou funcionalidades. Isso permite que usuários não autorizados executem ações, visualizem dados sensíveis ou acessem áreas administrativas que deveriam estar restritas.

Exemplo

Um sistema bancário que valida se o usuário está logado, mas não verifica se ele tem permissão para acessar a conta de outro cliente — bastaria mudar o ID na URL (ex: `/conta/123` para `/conta/456`) para ver dados alheios.

Como mitigar

Implemente verificações de autorização em todas as operações sensíveis, não confie apenas em obscuridade de URLs ou IDs. Use listas de controle de acesso (ACL) ou papéis (RBAC) centralizados, e valide permissões no servidor antes de retornar qualquer dado ou executar ação.

CVE-2026-27115HIGHADB Explorer is Vulnerable to Arbitrary Directory Deletion via Command-Line ArgumentEPSS 0.2%CVE-2026-46345HIGHcompliance-trestle - jinja has an Arbitrary File Write via Path TraversalEPSS 0.2%CVE-2026-81347MEDIUMFrontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.php Deletion via Custom Directory Path TraversalEPSS 0.2%CVE-2026-10559MEDIUMSourceCodester Pizzafy Ecommerce System index.php file inclusionEPSS 0.2%CVE-2026-10558MEDIUMSourceCodester Pizzafy Ecommerce System index.php file inclusionEPSS 0.2%CVE-2026-15382MEDIUMUltimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Deletion via delete-bsf-fontsEPSS 0.2%CVE-2026-79674HIGHNLTK 3.10.2 Path Traversal via corpus-reader constructorsEPSS 0.2%CVE-2026-19860MEDIUMJetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-Side Validation CallbackEPSS 0.2%CVE-2025-8998LOWIt was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. ThiEPSS 0.2%CVE-2026-66310HIGHMicrosoft Edge for Android Information Disclosure VulnerabilityEPSS 0.2%CVE-2024-4230HIGHExternal Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic SoftEPSS 0.2%CVE-2023-34982MEDIUMAVEVA Operations Control Logger External Control of File Name or Path EPSS 0.2%CVE-2024-25965MEDIUMDell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilegeEPSS 0.2%CVE-2026-25636HIGHcalibre has a Path Traversal Leading to Arbitrary File Corruption and Code ExecutionEPSS 0.2%CVE-2021-34761MEDIUMCisco Firepower Threat Defense Software CLI Arbitrary File Write VulnerabilityEPSS 0.2%CVE-2025-65799MEDIUMA lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traverEPSS 0.2%CVE-2021-1306MEDIUMCisco ADE-OS Local File Inclusion VulnerabilityEPSS 0.2%CVE-2026-54134HIGHOctoPrint: File exfiltration possible via query parameters on upload endpointsEPSS 0.2%CVE-2026-85160HIGHAVideo through c91b5975d CSRF and Path Traversal via stopLive.phpEPSS 0.2%CVE-2024-36473MEDIUMTrend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack but is limited to loEPSS 0.2%