CWE-306
2,579 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,579)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository. |
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cl...Show more |
1Motorola 2Ace Ip Gateway (4600) Firmware Moscad Ip Gateway FirmwareJun 17, 2026 Jul 26, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potent...Show more |
1Emerson 1Deltav Distributed Control System Jun 17, 2026 Jul 26, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (1...Show more |
1Bakerhughes 4Bently Nevada 3701/40 Firmware Bently Nevada 3701/44 FirmwareBently Nevada 3701/46 Firmware+1 moreJun 17, 2026 Jul 26, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and Sy...Show more |
1Jtekt 17Nano 10gx Tuc 1157 Firmware Nano Cpu Tuc 6941 FirmwarePc10b P Tcc 6373 Firmware+14 moreJun 17, 2026 Jul 26, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting an...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The spec...Show more |
The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of-service condition. |
1Johnsoncontrols 3Metasys Application And Data Server Metasys Extended Application And Data ServerMetasys Open Application ServerJun 17, 2026 Jul 22, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users. |
Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows changing the http[s]://wizardpwd.asp/cgi-bin. Does not validate the use...Show more |
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For m...Show more |
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For m...Show more |
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For m...Show more |
SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication. |
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An attacker can leverage th...Show more |
In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value. |
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without...Show more |
1Sap 1Business One License Service Api Jun 17, 2026 Jul 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can br...Show more |
1Siemens 6Simatic Mv540 H Firmware Simatic Mv540 S FirmwareSimatic Mv550 H Firmware+3 moreJun 17, 2026 Jul 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All vers...Show more |
1Siemens 1Simatic Easie Core Package Jun 17, 2026 Jul 12, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems does not perform authentication in the default configuration. This could allow an...Show more |