CWE-306
2,579 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,579)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Trumpf 3Trutops Boost Trutops FabTrutops MonitorJun 17, 2026 May 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unauthorized access to change of data or disruption of the whole service. |
USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product. |
Lexmark products through 2022-02-10 have Incorrect Access Control. |
Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managin...Show more |
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (Do...Show more |
The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with...Show more |
1Siteground 1Siteground Security Jun 17, 2026 Apr 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code impleme...Show more |
1Siteground 1Security Optimizer Jun 17, 2026 Apr 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allo...Show more |
1Combined Charging System Project 1Combined Charging System Firmware Jun 17, 2026 Apr 12, 2022 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Electric Vehicle (EV) commonly utilises the Combined Charging System (CCS) for DC rapid charging. To exchange important messages such as the State of Charge (SoC) with the Electric Vehicle Supply Equipment (EVSE) CCS use...Show more |
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint. |
Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authentication. In some operating modes this allows for an attacker to gain access...Show more |
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity docume...Show more |
An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update the configuraiton without authentication. |
1Drtrustusa 1Icheck Connect Bp Monitor Bp Testing 118 Firmware Jul 9, 2026 Apr 7, 2022 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication. |
1Sap Information System Project 1Sap Information System Jun 17, 2026 Apr 6, 2022 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/controllers/add_admin.php. An unauthenticated attacker is able to creat...Show more |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Apr 5, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name. |
AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity. |
The software does not perform any authentication for critical system functionality. |
1Redhat 2Openshift Container Platform Openshift Machine Config OperatorJun 17, 2026 Apr 1, 2022 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition c...Show more |
1Inductiveautomation 1Ignition Jun 17, 2026 Apr 1, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server |