CWE-306
2,579 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,579)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pingidentity 1Pingid Integration For Windows Login Jun 17, 2026 Jun 30, 2022 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to expl...Show more |
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts. |
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address. |
1Illumina 1Local Run Manager Jun 17, 2026 Jun 24, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data. |
1Shinasys 3Sihas Acm 300 Firmware Sihas Gcm 300 FirmwareSihas Sgw 300 FirmwareJun 17, 2026 Jun 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device. |
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This i...Show more |
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which...Show more |
AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights. |
Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for...Show more |
An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers. |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Jun 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentication verification for a resource used to change the roles and permissions of a user. This could allo...Show more |
1Siemens 1Sicam Gridedge Essential Jun 17, 2026 Jun 14, 2022 9.3 CRITICAL· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attack...Show more |
1Siemens 1Sicam Gridedge Essential Jun 17, 2026 Jun 14, 2022 8.6 HIGH· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attack...Show more |
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a...Show more |
The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on t...Show more |
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg. |
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization. |
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization. |
1Owllabs 1Meeting Owl Pro Firmware Jun 17, 2026 Jun 2, 2022 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 message. |
1Barco 1Control Room Management Suite Jun 17, 2026 Jun 2, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication. |