← Back
CWE-306

2,645 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,645)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Dec 30, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require auth...Show more
Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7.Show less
1Kioxia
3Cm6 Firmware
Pm6 FirmwarePm7 Firmware
Jun 17, 2026
Dec 20, 2024
5.7 MEDIUM· v4
6.8 MEDIUM· v3
N/A· v2
There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives it was discovered that the 2 main CPU cores of the SoC can be accessed via an open...Show more
There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives it was discovered that the 2 main CPU cores of the SoC can be accessed via an open JTAG debug port that is exposed on the drive’s circuit board. Due to the wide cutout of the enclosures, the JTAG port can be accessed without having to open the disk enclosure. Utilizing the JTAG debug port, an attacker with (temporary) physical access can get full access to the firmware and memory on the 2 main CPU cores within the drive including the execution of arbitrary code, the modification of firmware execution flow and data or bypassing the firmware signature verification during boot-up.Show less
-
-
Jun 17, 2026
Dec 19, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the supplier.
-
-
Jun 17, 2026
Dec 19, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.
-
-
Jun 17, 2026
Dec 18, 2024
9.3 CRITICAL· v4
N/A· v3
N/A· v2
A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most p...Show more
A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset.Show less
-
-
Jun 17, 2026
Dec 17, 2024
N/A· v4
7.9 HIGH· v3
N/A· v2
Locally installed application can bypass the permission check and perform system operations that require permission.
-
-
Jun 17, 2026
Dec 17, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.
-
-
Jun 17, 2026
Dec 17, 2024
N/A· v4
6.4 MEDIUM· v3
N/A· v2
When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a carefully constructed wifi with the same name, which can lead t...Show more
When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a carefully constructed wifi with the same name, which can lead to man-in-the-middle attacks.Show less
-
-
Jun 17, 2026
Dec 17, 2024
N/A· v4
9.4 CRITICAL· v3
N/A· v2
Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Anal...Show more
Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Analytics component ).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.3-00; Hitachi Infrastructure Analytics Advisor: from 2.1.0-00 through 4.4.0-00.Show less
1Ivanti
1Cloud Services Appliance
Jun 17, 2026
Dec 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
-
-
Jun 17, 2026
Dec 6, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write files or load apps that use al...Show more
Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write files or load apps that use all features of the product available to a customer.Show less
-
-
Jun 17, 2026
Dec 6, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web application without authentication.
1Jetbrains
1Youtrack
Jun 17, 2026
Dec 4, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
1Jetbrains
1Youtrack
Jun 17, 2026
Dec 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Dec 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate...Show more
A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate used for authentication on a specific port. This can result in unauthorized access, enabling the user to call privileged methods and initiate critical services. The issue arises due to insufficient permission requirements on the method, allowing users with low privileges to perform actions that should require higher-level permissions.Show less
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Dec 4, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the a...Show more
A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service account privileges. The vulnerability is caused by an insufficient blacklist during the deserialization process.Show less
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Dec 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, w...Show more
A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The user can update a job and schedule it to run almost immediately, allowing arbitrary code execution on the server.Show less
1Matrix
1Synapse
Jun 17, 2026
Dec 3, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local med...Show more
Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media repository. Such content then also becomes available for download from the local homeserver in an unauthenticated way. The implication is that unauthenticated remote adversaries can use this functionality to plant problematic content into the media repository. Synapse 1.106 introduces a partial mitigation in the form of new endpoints which require authentication for media downloads. The unauthenticated endpoints will be frozen in a future release, closing the attack vector.Show less
-
-
Jun 17, 2026
Dec 2, 2024
8.8 HIGH· v4
N/A· v3
N/A· v2
A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and c...Show more
A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and can make a request to unclaim it from its original connection and make a request to claim it.Show less
-
-
Jun 17, 2026
Nov 29, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.