← Back
CWE-306

2,630 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,630)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sigb
1Pmb
Jun 17, 2026
May 27, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution.
1Tcman
1Gim
Jun 17, 2026
May 26, 2025
9.3 CRITICAL· v4
9.1 CRITICAL· v3
N/A· v2
Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, /frmGestionUser.aspx/updateUser and /frmGestionUser.aspx/DeleteUser.
-
-
Jun 17, 2026
May 26, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An unauthenticated remote attacker can access a URL which causes the device to reboot.
-
-
Jun 17, 2026
May 26, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of returned data can trigger a reboot by the watchdog.
-
-
Jun 17, 2026
May 21, 2025
10.0 CRITICAL· v4
10.0 CRITICAL· v3
N/A· v2
The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the enviro...Show more
The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality.Show less
1Smartbedded
2Meteobridge Firmware
Meteobridge Vm
Jun 17, 2026
May 21, 2025
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web int...Show more
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.Show less
-
-
Jun 17, 2026
May 21, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary a...Show more
The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
May 20, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
1Jetbrains
1Youtrack
Jun 17, 2026
May 20, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning
-
-
Jun 17, 2026
May 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier. If exploited, a remote unauthenticated attacker may change the product settin...Show more
Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier. If exploited, a remote unauthenticated attacker may change the product settings.Show less
-
-
Jun 17, 2026
May 14, 2025
6.9 MEDIUM· v4
N/A· v3
N/A· v2
A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM.  The attacker must have network access to the Brok...Show more
A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM.  The attacker must have network access to the Broker VM to exploit this issue.Show less
1Netalertx
1Netalertx
Jun 17, 2026
May 13, 2025
N/A· v4
10.0 CRITICAL· v3
N/A· v2
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This i...Show more
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.Show less
1Cpplusworld
1Cp Xr De21 S Firmware
Jun 17, 2026
May 13, 2025
N/A· v4
5.1 MEDIUM· v3
N/A· v2
CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read...Show more
CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read all boot sequence, and revealing internal system details and sensitive information without any authentication.Show less
-
-
Jun 17, 2026
May 13, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of a highly protected zone), Desigo CC (All versions if access from Ins...Show more
A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of a highly protected zone), Desigo CC (All versions if access from Installed Clients to Desigo CC server is only allowed within highly protected zones). The affected server application fails to authenticate specific client requests. Modification of the client binary could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database via the event port (default: 4998/tcp)Show less
-
-
Jun 17, 2026
May 12, 2025
6.9 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access certain system functions. These functions include viewing the administrator list, viewing and...Show more
The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access certain system functions. These functions include viewing the administrator list, viewing and editing IP settings, and uploading files.Show less
-
-
Jun 17, 2026
May 12, 2025
8.8 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific APIs and operate system functions. These functions incl...Show more
The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific APIs and operate system functions. These functions include opening gates and restarting the system.Show less
-
-
Jun 17, 2026
May 12, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system functions. These functions in...Show more
The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system functions. These functions include opening gates, viewing license plates and parking records, and restarting the system.Show less
-
-
Jun 30, 2026
May 9, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys stored in the TPM, it reads the decryption key int...Show more
A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys stored in the TPM, it reads the decryption key into system memory. If an attacker with physical access can corrupt the underlying filesystem superblock, GRUB will fail to locate a valid filesystem and enter rescue mode. At this point, the disk is already decrypted, and the decryption key remains loaded in system memory. This scenario may allow an attacker with physical access to access the unencrypted data without any further authentication, thereby compromising data confidentiality. Furthermore, the ability to force this state through filesystem corruption also presents a data integrity concern.Show less
-
-
Jun 17, 2026
May 8, 2025
8.7 HIGH· v4
N/A· v3
N/A· v2
Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP...Show more
Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about this disclosure but did not respond in any way.Show less
-
-
Jun 17, 2026
May 8, 2025
8.7 HIGH· v4
N/A· v3
N/A· v2
WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosur...Show more
WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosure but did not respond in any way.Show less