CWE-306
2,579 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,579)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s filesystem where the blev...Show more |
5Brocade DebianHaxx+2 more12Bootstrap Os Clustered Data OntapCurl+9 moreJun 17, 2026 May 26, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the...Show more |
1Openautomationsoftware 1Oas Platform Jun 17, 2026 May 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to a disclosure of sensit...Show more |
1Openautomationsoftware 1Oas Platform Jun 17, 2026 May 25, 2022 N/A· v4 9.4 CRITICAL· v3 7.5 HIGH· v2 An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST...Show more |
1Openautomationsoftware 1Oas Platform Jun 17, 2026 May 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation...Show more |
1Openautomationsoftware 1Oas Platform Jun 17, 2026 May 25, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to remote code execution...Show more |
1Openautomationsoftware 1Oas Platform Jun 17, 2026 May 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to arbitrar...Show more |
1Openautomationsoftware 1Oas Platform Jun 17, 2026 May 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creat...Show more |
1Openautomationsoftware 1Oas Platform Jun 17, 2026 May 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to loss of communications. An...Show more |
TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the UART port via a serial connection and execute commands as the root use...Show more |
1Ibm 1Power System S922 Firmware Jun 17, 2026 May 24, 2022 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability can be more critical if the serial port is connected to a serial-over-lan device. IBM X-Force ID: 21...Show more |
The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=e...Show more |
1Siemens 367kg8500 0aa00 0aa0 Firmware 7kg8500 0aa00 2aa0 Firmware7kg8500 0aa10 0aa0 Firmware+33 moreJun 17, 2026 May 20, 2022 6.9 MEDIUM· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pages of the web interface. This could allow an attacker to delete log files withou...Show more |
1Siemens 367kg8500 0aa00 0aa0 Firmware 7kg8500 0aa00 2aa0 Firmware7kg8500 0aa10 0aa0 Firmware+33 moreJun 17, 2026 May 20, 2022 6.9 MEDIUM· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected devices does not employ special access protection for certain internal developer views. This could allo...Show more |
1Siemens 367kg8500 0aa00 0aa0 Firmware 7kg8500 0aa00 2aa0 Firmware7kg8500 0aa10 0aa0 Firmware+33 moreJun 17, 2026 May 20, 2022 5.3 MEDIUM· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected devices does not employ special access protection for certain internal developer views. This could allo...Show more |
1Siemens 367kg8500 0aa00 0aa0 Firmware 7kg8500 0aa00 2aa0 Firmware7kg8500 0aa10 0aa0 Firmware+33 moreJun 17, 2026 May 20, 2022 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM...Show more |
1Microsoft 17Windows 10 1507 Windows 10 1607Windows 10 1809+14 moreJun 17, 2026 May 10, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Windows LSA Spoofing Vulnerability |
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users |
On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 May 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass i...Show more |