← Back
CWE-306

2,600 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,600)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sick
2Fx0 Gpnt00000 Firmware
Fx0 Gpnt00010 Firmware
Jun 17, 2026
Feb 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands t...Show more
Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.Show less
1Sir
1Gnuboard
Jun 17, 2026
Feb 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original password.
1Apolloconfig
1Apollo
Jun 17, 2026
Feb 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authent...Show more
Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature enabled for the built-in eureka service. Malicious hackers may access eureka directly to mock apollo-configservice and apollo-adminservice. Login authentication for eureka was added in version 2.1.0. As a workaround, avoid exposing apollo-configservice to the internet.Show less
1Kavitareader
1Kavita
Jun 17, 2026
Feb 19, 2023
N/A· v4
3.5 LOW· v3
N/A· v2
Missing Authentication for Critical Function in GitHub repository kareadita/kavita prior to 0.7.0.
1Online Pizza Ordering System Project
1Online Pizza Ordering System
Jun 17, 2026
Feb 18, 2023
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0. Affected by this vulnerability is the function delete_category of the file ajax.php of the component POST Parameter Han...Show more
A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0. Affected by this vulnerability is the function delete_category of the file ajax.php of the component POST Parameter Handler. The manipulation leads to missing authentication. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-221455.Show less
1Tianjie
2Cpe906 3
Cpe906 3 Firmware
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
TIANJIE CPE906-3 is vulnerable to password disclosure. This is present on Software Version WEB5.0_LCD_20200513, Firmware Version MV8.003, and Hardware Version CPF906-V5.0_LCD_20200513.
1Palantir
1Gotham
Jun 17, 2026
Feb 16, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have been patched and automatically deployed to all Apollo-managed Gotham i...Show more
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have been patched and automatically deployed to all Apollo-managed Gotham instances. It is highly recommended that customers upgrade all affected services to the latest version. This issue affects: Palantir Gotham versions prior to 103.30221005.0.Show less
1Ls Electric
1Xbc Dn32u Firmware
Jun 17, 2026
Feb 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to create and use an account with elevated privileges and take control of the d...Show more
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to create and use an account with elevated privileges and take control of the device. Show less
1Ls Electric
1Xbc Dn32u Firmware
Jun 17, 2026
Feb 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the PLC. This could allow an attacker to change the PLC's mode arbitrarily.
1Ls Electric
1Xbc Dn32u Firmware
Jun 17, 2026
Feb 15, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could allow an attacker to delete arbitrary files.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Feb 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Feb 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Feb 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Feb 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
1Br Automation
1Industrial Automation Aprol
Jun 17, 2026
Feb 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration. 
1Microchip
1Rn4870 Firmware
Jun 17, 2026
Feb 8, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.
1Terra Master
1Terramaster Operating System
Jun 17, 2026
Feb 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
1Unifiedremote
1Unified Remote
Jun 17, 2026
Feb 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unifi...Show more
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's choosing.Show less
1Modern Honey Network Project
1Modern Honey Network
Jun 17, 2026
Feb 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensitive information via crafted PUT request to Web API.
1In2code
1Femanager
Jun 17, 2026
Feb 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend us...Show more
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.Show less