CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 1C Bus Toolkit Jun 17, 2026 Jul 21, 2021 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system. |
1Schneider Electric 3T200e Firmware T200i FirmwareT200p FirmwareJun 17, 2026 Jul 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-07000100 and earlier), Easergy T200 ((IEC104) SC2-04IEC-07000100 and earlier), and Easergy T200 ((DNP3) SC2...Show more |
An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings and GetNetworkSettings without authentic...Show more |
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed. |
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access page...Show more |
An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have alread...Show more |
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
1Commscope 1Ruckus Iot Controller Jun 17, 2026 Jul 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints. |
1Properfraction 1Profilepress Jun 17, 2026 Jul 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue...Show more |
1Sloan 71Basys Efx 100 Firmware Basys Efx 150 FirmwareBasys Efx 175 Firmware+68 moreJun 17, 2026 Jun 30, 2021 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and info...Show more |
1Westerndigital 2Wd My Book Live Duo Firmware Wd My Book Live FirmwareJun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a...Show more |
1Siemens 3Sinamics Sl150 Firmware Sinamics Sm150 FirmwareSinamics Sm150i FirmwareJun 17, 2026 Jun 28, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote attacker to gain access to the device if the service is enabled. Telnet...Show more |
Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users are recommend to update to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly...Show more |
1Dlink 1Dsl 2888a Firmware Jun 17, 2026 Jun 24, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the password of the admin user without authorization. |
1Ballerina 2Ballerina Swan LakeJun 17, 2026 Jun 22, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.x and SL releases up to alpha 3 have a potential for a supply chain attack via MiTM against users. H...Show more |
1White Shark Systems Project 1White Shark Systems Jun 17, 2026 Jun 21, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does not have an authentication operation. Remote attackers can obtain username information for all users o...Show more |
1Matrix 1Matrix Appservice Bridge Jun 17, 2026 Jun 16, 2021 N/A· v4 4.9 MEDIUM· v3 3.5 LOW· v2 Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In versions 2.6.0 and earlier, if a bridge has room upgrade handling turned on in the configuration (the `room...Show more |
The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arbitrary code on the iView (versions prior to v5.7.03.6182). |
1Bosch 3Cpp6 Firmware Cpp7.3 FirmwareCpp7 FirmwareJun 17, 2026 Jun 9, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Onl...Show more |
BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for example, include Tigera products in some configurations, as well as prod...Show more |