CWE-306
2,579 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,579)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. As a result, the attacker...Show more |
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a predictable /log URI. |
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to process...Show more |
1Zohocorp 3Manageengine Servicedesk Plus Manageengine Servicedesk Plus MspManageengine Supportcenter PlusJun 17, 2026 Nov 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servl...Show more |
1Dlink 1Dwr 932c E1 Firmware Jun 17, 2026 Nov 23, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows an unauthenticated attacker to execute administrative actions. |
In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client. |
Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage project. Affected versions are subject to an authentication bypass issue in the Operator Console when a...Show more |
1Zohocorp 1Manageengine Log360 Jun 17, 2026 Nov 1, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to c...Show more |
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history. |
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. By default, SIP requests of the type...Show more |
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH d...Show more |
1Emerson 3Wireless 1410 Gateway Firmware Wireless 1410d Gateway FirmwareWireless 1420 Gateway FirmwareJun 17, 2026 Oct 22, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved settings change. |
The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication. |
1Siemens 4Simatic Process Historian 2013 Simatic Process Historian 2014Simatic Process Historian 2019+1 moreJun 17, 2026 Oct 12, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 Update 6), SIMATIC Process Historian 2019 (All versions), SIMATIC Proce...Show more |
1Tad Uploader Project 1Tad Uploader Jun 17, 2026 Oct 8, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in. |
1Tadtools Project 1Tadtools Jun 17, 2026 Oct 8, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in. |
1Tad Book3 Project 1Tad Book3 Jun 17, 2026 Oct 8, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission. |
Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin boards and uploading files in the system. |
1Digi 186350 Sr Firmware Cm FirmwareConnect Es Firmware+15 moreJun 17, 2026 Oct 8, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication. |
1Bosch 12Indracontrol Xlc Firmware Rexroth Indramotion Mlc L20 FirmwareRexroth Indramotion Mlc L25 Firmware+9 moreJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are ex...Show more |