← Back
CWE-306

2,645 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,645)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Realtyworkstation
1Realty Workstation
Jun 17, 2026
Oct 28, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through <= 1....Show more
Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through <= 1.0.45.Show less
1Maantheme
1Maanstore Api
Jun 17, 2026
Oct 28, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authentication Bypass.This issue affects MaanStore API: from n/a through <= 1.0.1.
1Acnoo
1Flutter Api
Jun 17, 2026
Oct 28, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through <= 1.0.5.
1Stacksmarket
1Stacks Mobile App Builder
Jun 17, 2026
Oct 28, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a thr...Show more
Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.Show less
1Rockwellautomation
1Thinmanager
Jun 17, 2026
Oct 25, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in d...Show more
CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation.Show less
2Sharp
Toshibatec
320Bp 30c25 Firmware
Bp 30c25t FirmwareBp 30c25y Firmware+317 more
Jun 17, 2026
Oct 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.
-
-
Jun 17, 2026
Oct 24, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers to access the SSH protocol without authentication.
1Siemens
2Intermesh 7177 Hybrid 2.0 Subscriber
Intermesh 7707 Fire Subscriber Firmware
Jun 17, 2026
Oct 23, 2024
6.9 MEDIUM· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default c...Show more
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not authenticate GET requests that execute specific commands (such as `ping`) on operating system level.Show less
1Fortinet
2Fortimanager
Fortimanager Cloud
Jun 17, 2026
Oct 23, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager...Show more
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.Show less
-
-
Jun 17, 2026
Oct 22, 2024
N/A· v4
9.0 CRITICAL· v3
N/A· v2
An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the /www/cgi-bin/nas.cgi component.
1Ysoft
1Safeq
Jun 17, 2026
Oct 22, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet attacks. Because the service did not enforce authentication and was runni...Show more
A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet attacks. Because the service did not enforce authentication and was running under the "NT Authority\System" user, an attacker is able to use the vulnerability to execute arbitrary code and elevate to the system user.Show less
1Roveridx
1Rover Idx
Jun 17, 2026
Oct 22, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. This is due to insufficient validation and capability check on the 'rover_idx_refresh_social_callbac...Show more
The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. This is due to insufficient validation and capability check on the 'rover_idx_refresh_social_callback' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in to administrator. The vulnerability is partially patched in version 3.0.0.2905 and fully patched in version 3.0.0.2906.Show less
1Viloliving
1Vilo 5 Firmware
Jul 5, 2026
Oct 21, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Vilo 5 Mesh WiFi System <= 5.16.1.33 lacks authentication in the Boa webserver, which allows remote, unauthenticated attackers to retrieve logs with sensitive system.
1Viloliving
1Vilo 5 Firmware
Jul 5, 2026
Oct 21, 2024
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP service on port 5432 allows remote, unauthenticated attackers to gain administrative access over the ro...Show more
Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP service on port 5432 allows remote, unauthenticated attackers to gain administrative access over the router.Show less
1Mitel
1Micollab
Jun 17, 2026
Oct 21, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to perform unauthorized data-access attacks due to missi...Show more
A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to perform unauthorized data-access attacks due to missing authentication mechanisms. A successful exploit could allow an attacker to access and delete sensitive information.Show less
1Najeebmedia
1Simple User Registration
Jun 17, 2026
Oct 20, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7...Show more
Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.Show less
1Vivektamrakar
1Wp Rest Api Fns
Jun 17, 2026
Oct 20, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through <= 1.0.0.
-
-
Jun 17, 2026
Oct 17, 2024
8.7 HIGH· v4
N/A· v3
N/A· v2
The affected product is vulnerable to an attacker being able to use commands without providing a password which may allow an attacker to leak information.
-
-
Jun 17, 2026
Oct 17, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform admin-level operati...Show more
PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform admin-level operations, potentially compromising sensitive data and system integrity. This problem has been fixed in v2.1.0.beta.1. As a workaround, one may apply the patch from commit `211dfe9` manually.Show less
1Miniorange
1Otp Verification With Firebase
Jun 17, 2026
Oct 17, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the...Show more
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the phone number associated with that user.Show less