CWE-306
2,604 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,604)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This is due to the use of a user supplied hashing algorithm passed to the hash_hmac() function and the use...Show more |
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it pos...Show more |
1Wisetr 1User Email Verification For Woocommerce Jun 17, 2026 Jun 3, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation wea...Show more |
1Chuanhuchatgpt Project 1Chuanhuchatgpt Jun 17, 2026 Jun 2, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 ChuanhuChatGPT is a graphical user interface for ChatGPT and many large language models. A vulnerability in versions 20230526 and prior allows unauthorized access to the config.json file of the privately deployed Chuangh...Show more |
It is identified a vulnerability of insufficient authentication in the system configuration interface of Hitron Technologies CODA-5310. An unauthorized remote attacker can exploit this vulnerability to access system conf...Show more |
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to...Show more |
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the...Show more |
1Honeywell 1Onewireless Network Wireless Device Manager Firmware Jun 17, 2026 May 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1 |
Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server shoul...Show more |
The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may affect device confidentiality. |
The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect availability. |
IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network. |
Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affects HYPR Server: before 8.0 (with enabled Legacy APIs)
|
2Especmic Tandd10Rs 12n Firmware Rt 12n FirmwareRt 22bn Firmware+7 moreJun 17, 2026 May 23, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Missing authentication for critical function exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may allow a remote unauthenticated attacker to alter the product settings without authentication. Aff...Show more |
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through...Show more |
Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with native query editing permissions to a database–but affected versions of Me...Show more |
1Cisco 8Business 140ac Access Point Firmware Business 141acm FirmwareBusiness 142acm Firmware+5 moreJun 17, 2026 May 18, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vu...Show more |
SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user. |
1Sick 11Fx0 Gent00000 Firmware Fx0 Gent00010 FirmwareFx0 Gent00030 Firmware+8 moreJun 17, 2026 May 12, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 1044072, 1044073, 1044074, 1099830, 1099832, 1127717, 1069070, 1112296, 1051432, 1102...Show more |
1Seiko Sol 2Skybridge Mb A100 Firmware Skybridge Mb A110 FirmwareJun 17, 2026 May 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Missing authentication for critical function exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to execute some critical functions without authentication, e...Show more |