CWE-306
2,579 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,579)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, a...Show more |
In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no add...Show more |
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE v...Show more |
1Iclinks 2Scadaflex Ii Firmware WeblibJun 17, 2026 Feb 26, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files. |
1Emerson 1Openenterprise Scada Server Jun 17, 2026 Feb 24, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service. |
1Antd Admin Project 1Antd Admin Jun 17, 2026 Feb 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information. |
1Emerson 1Dixell Xweb 500 Firmware Jul 9, 2026 Feb 14, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the t...Show more |
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout. |
1Schneider Electric 1Interactive Graphical Scada System Data Collector Jun 17, 2026 Feb 11, 2022 N/A· v4 9.1 CRITICAL· v3 5.0 MEDIUM· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Pr...Show more |
1Schneider Electric 1Interactive Graphical Scada System Data Collector Jun 17, 2026 Feb 11, 2022 N/A· v4 9.1 CRITICAL· v3 5.0 MEDIUM· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Pr...Show more |
1Stormshield 1Stormshield Network Security Jun 17, 2026 Feb 10, 2022 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client. |
In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requi...Show more |
1Schneider Electric 3Fellerlynk Firmware Spacelynk FirmwareWiser For Knx FirmwareJun 17, 2026 Feb 9, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configuratio...Show more |
1Nvidia 2Cloud Gaming Virtual Gpu Virtual GpuJun 17, 2026 Feb 7, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on the hypervisor host, leading to a denial of service. |
1Sealevel 1Seaconnect 370w Firmware Jun 17, 2026 Feb 4, 2022 N/A· v4 7.4 HIGH· v3 7.1 HIGH· v2 A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send...Show more |
2Motioneye Project Motioneyeos Project2Motioneye MotioneyeosJun 17, 2026 Jan 31, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrar...Show more |
1Emerson 2Deltav Distributed Control System Deltav WorkstationJun 17, 2026 Jan 28, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service condition. |
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. Th...Show more |
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1. |
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. |