CWE-306
2,600 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,600)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 23Lax20 Firmware R6400 FirmwareR6700 Firmware+20 moreJun 17, 2026 Mar 29, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists w...Show more |
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0
Description: Attacker can elevate their privileges in any room
|
The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality. |
1Deltaww 1Infrasuite Device Master Jun 17, 2026 Mar 27, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator. |
HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator's credential. This credential can then be used to login PowerSt...Show more |
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication. |
LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function. |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Mar 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achie...Show more |
1Schneider Electric 3Custom Reports Igss DashboardIgss Data ServerJun 17, 2026 Mar 21, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data w...Show more |
1Schneider Electric 3Custom Reports Igss DashboardIgss Data ServerJun 17, 2026 Mar 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead...Show more |
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication....Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Mar 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure h...Show more |
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts. |
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could acce...Show more |
An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint. |
VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode. |
1Wago 7751 9301 Firmware 752 8303/8000 002 FirmwarePfc100 Firmware+4 moreJun 17, 2026 Feb 27, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise. |
1Wago 7751 9301 Firmware 752 8303/8000 002 FirmwarePfc100 Firmware+4 moreJun 17, 2026 Feb 27, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read an...Show more |
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. Therefore, an attacker...Show more |
1Sick 2Fx0 Gent00000 Firmware Fx0 Gent00010 FirmwareJun 17, 2026 Feb 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands t...Show more |