← Back
CWE-306

2,579 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,579)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trumpf
3Trutops Boost
Trutops FabTrutops Monitor
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unauthorized access to change of data or disruption of the whole service.
1Usu
1Oracle Optimization
Jun 17, 2026
Apr 29, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product.
1Lexmark
1Lexmark Firmware
Jun 17, 2026
Apr 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Lexmark products through 2022-02-10 have Incorrect Access Control.
1Hammock
1Assetview
Jun 17, 2026
Apr 28, 2022
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managin...Show more
Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative privilege.Show less
1Zammad
1Zammad
Jun 17, 2026
Apr 27, 2022
N/A· v4
9.1 CRITICAL· v3
5.8 MEDIUM· v2
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (Do...Show more
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).Show less
1Brandexponents
1Tatsu
Jun 17, 2026
Apr 25, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with...Show more
The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. Moreover, there is a race condition in the zip extraction process which makes the shell file live long enough on the filesystem to be callable by an attacker.Show less
1Siteground
1Siteground Security
Jun 17, 2026
Apr 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code impleme...Show more
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects versions up to, and including, 1.2.5.Show less
1Siteground
1Security Optimizer
Jun 17, 2026
Apr 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allo...Show more
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA for pending accounts. Upon successful configuration, the attacker is logged in as that user without access to a username/password pair which is the expected first form of authentication. This affects versions up to, and including, 1.2.5.Show less
1Combined Charging System Project
1Combined Charging System Firmware
Jun 17, 2026
Apr 12, 2022
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Electric Vehicle (EV) commonly utilises the Combined Charging System (CCS) for DC rapid charging. To exchange important messages such as the State of Charge (SoC) with the Electric Vehicle Supply Equipment (EVSE) CCS use...Show more
Electric Vehicle (EV) commonly utilises the Combined Charging System (CCS) for DC rapid charging. To exchange important messages such as the State of Charge (SoC) with the Electric Vehicle Supply Equipment (EVSE) CCS uses a high-bandwidth IP link provided by the HomePlug Green PHY (HPGP) power-line communication (PLC) technology. The attack interrupts necessary control communication between the vehicle and charger, causing charging sessions to abort. The attack can be conducted wirelessly from a distance using electromagnetic interference, allowing individual vehicles or entire fleets to be disrupted simultaneously. In addition, the attack can be mounted with off-the-shelf radio hardware and minimal technical knowledge. With a power budget of 1 W, the attack is successful from around 47 m distance. The exploited behavior is a required part of the HomePlug Green PHY, DIN 70121 & ISO 15118 standards and all known implementations exhibit it. In addition to electric cars, Brokenwire affects electric ships, airplanes and heavy duty vehicles utilising these standards.Show less
1Vfbpro
1Visual Form Builder
Jun 17, 2026
Apr 12, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
1Garden
1Garden
Jun 17, 2026
Apr 11, 2022
N/A· v4
9.8 CRITICAL· v3
4.3 MEDIUM· v2
Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authentication. In some operating modes this allows for an attacker to gain access...Show more
Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authentication. In some operating modes this allows for an attacker to gain access to the application erroneously. The configuration is leaked through the /api endpoint on the local server that is responsible for serving the Garden dashboard. At the moment, this server is accessible to 0.0.0.0 which makes it accessible to anyone on the same network (or anyone on the internet if they are on a public, static IP). This may lead to the ability to compromise credentials, secrets or environment variables. Users are advised to upgrade to version 0.12.39 as soon as possible. Users unable to upgrade should use a firewall blocking access to port 9777 from all untrusted network machines.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Apr 8, 2022
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity docume...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.Show less
1Claro
1Kaon Cg3000 Firmware
Jun 17, 2026
Apr 8, 2022
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update the configuraiton without authentication.
1Drtrustusa
1Icheck Connect Bp Monitor Bp Testing 118 Firmware
Jul 9, 2026
Apr 7, 2022
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.
1Sap Information System Project
1Sap Information System
Jun 17, 2026
Apr 6, 2022
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/controllers/add_admin.php. An unauthenticated attacker is able to creat...Show more
A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/controllers/add_admin.php. An unauthenticated attacker is able to create a new admin account for the web application with a simple POST request. Exploit details were disclosed.Show less
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Apr 5, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
1Aveva
1System Platform
Jun 17, 2026
Apr 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity.
1Philips
1E Alert Firmware
Jun 17, 2026
Apr 1, 2022
N/A· v4
6.5 MEDIUM· v3
5.7 MEDIUM· v2
The software does not perform any authentication for critical system functionality.
1Redhat
2Openshift Container Platform
Openshift Machine Config Operator
Jun 17, 2026
Apr 1, 2022
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition c...Show more
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition configuration used for bootstrapping Nodes and can include some sensitive data, e.g. registry pull secrets. There are two scenarios where this data can be accessed. The first is on Baremetal, OpenStack, Ovirt, Vsphere and KubeVirt deployments which do not have a separate internal API endpoint and allow access from outside the cluster to port 22623 from the standard OpenShift API Virtual IP address. The second is on cloud deployments when using unsupported network plugins, which do not create iptables rules that prevent to port 22623. In this scenario, the ignition config is exposed to all pods within the cluster and cannot be accessed externally.Show less
1Inductiveautomation
1Ignition
Jun 17, 2026
Apr 1, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server