CWE-306
2,613 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Supplier Relationship Management Jun 17, 2026 Aug 8, 2023 N/A· v4 5.8 MEDIUM· v3 N/A· v2 SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master Data for Business Partners replication f...Show more |
SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy. |
Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn call read functions. This allows the att...Show more |
1Samsung 33Fgn1115 Wp Wh Firmware Fgn1122 Cd FirmwareFgn1122 Sa Firmware+30 moreJun 17, 2026 Jul 20, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The web interface on multiple Samsung Harman AMX N-Series devices allows directory listing for the /tmp/ directory, without authentication, exposing sensitive information such as the command history and screenshot of the...Show more |
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated a...Show more |
1Kratosdefense 1Ngc Indoor Unit Firmware Jun 17, 2026 Jul 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to th...Show more |
AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit of this vulnerability may lead to loss of confidentiality, integrity, an...Show more |
CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving t...Show more |
The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a zero-length pass0 to the webcontrol changepwd.cgi application, i.e., the...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Jul 11, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERN...Show more |
1Sap 1Netweaver Process Integration Jun 17, 2026 Jul 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might acc...Show more |
1Sap 1Netweaver Process Integration Jun 17, 2026 Jul 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might ac...Show more |
Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloaded applications. |
1Heroelectronix 2Qubo Hcd01 Firmware Qubo Hcd02 FirmwareJun 17, 2026 Jul 4, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password. |
A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data. |
The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through th...Show more |
1Stw Mobile Machines 2Tcg 4 Firmware Tcg 4lite FirmwareJun 17, 2026 Jun 29, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCG-4lite Connectivity Module DeploymentPackage_v3.04r2-Jellyfish allow an attacke...Show more |
An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypass the application's client-side chat censor filter. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Jun 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain cont...Show more |
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized. |