← Back
CWE-306

2,579 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,579)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Simple Diagnostics Agent
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, a...Show more
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could access administrative or other privileged functionalities and read, modify, or delete sensitive information and configurations.Show less
1Google
1Android
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.6 MEDIUM· v3
4.4 MEDIUM· v2
In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no add...Show more
In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06137462.Show less
1Mingsoft
1Mcms
Jun 17, 2026
Mar 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE v...Show more
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to compromise MCMS. Successful attacks of this vulnerability can result in takeover of MCMS.Show less
1Iclinks
2Scadaflex Ii Firmware
Weblib
Jun 17, 2026
Feb 26, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
1Emerson
1Openenterprise Scada Server
Jun 17, 2026
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.
1Antd Admin Project
1Antd Admin
Jun 17, 2026
Feb 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.
1Emerson
1Dixell Xweb 500 Firmware
Jul 9, 2026
Feb 14, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the t...Show more
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced.Show less
1Niteothemes
1Cmp
Jun 17, 2026
Feb 14, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
1Schneider Electric
1Interactive Graphical Scada System Data Collector
Jun 17, 2026
Feb 11, 2022
N/A· v4
9.1 CRITICAL· v3
5.0 MEDIUM· v2
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Pr...Show more
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)Show less
1Schneider Electric
1Interactive Graphical Scada System Data Collector
Jun 17, 2026
Feb 11, 2022
N/A· v4
9.1 CRITICAL· v3
5.0 MEDIUM· v2
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Pr...Show more
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)Show less
1Stormshield
1Stormshield Network Security
Jun 17, 2026
Feb 10, 2022
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client.
1Mahara
1Mahara
Jun 17, 2026
Feb 10, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requi...Show more
In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known.Show less
1Schneider Electric
3Fellerlynk Firmware
Spacelynk FirmwareWiser For Knx Firmware
Jun 17, 2026
Feb 9, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configuratio...Show more
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)Show less
1Nvidia
2Cloud Gaming Virtual Gpu
Virtual Gpu
Jun 17, 2026
Feb 7, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on the hypervisor host, leading to a denial of service.
1Sealevel
1Seaconnect 370w Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
7.4 HIGH· v3
7.1 HIGH· v2
A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send...Show more
A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.Show less
2Motioneye Project
Motioneyeos Project
2Motioneye
Motioneyeos
Jun 17, 2026
Jan 31, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrar...Show more
Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server.Show less
1Emerson
2Deltav Distributed Control System
Deltav Workstation
Jun 17, 2026
Jan 28, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service condition.
1Netgear
1Xr1000
Jun 17, 2026
Jan 25, 2022
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. Th...Show more
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP messages. The issue results from a lack of authentication required for a privileged request. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-13325.Show less
1Apache
1Shenyu
Jun 17, 2026
Jan 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
1Apache
1Shenyu
Jun 17, 2026
Jan 25, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.