CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality. |
There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Attackers with physical access to the device can thereby exploit this vulnerability. A successful exploitation of this vulnerabi...Show more |
1Redhat 23scale 3scale Api ManagementJun 17, 2026 May 26, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affe...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 May 26, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A mal...Show more |
A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw allows an attacker to take control of an X application by impersonating the server it is expecting t...Show more |
2Codesys Wago28750 8202 Firmware 750 8203 Firmware750 8204 Firmware+25 moreJun 17, 2026 May 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control. |
SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network, to access via HTTP to the internal configuration database of the device without any authentication. An attacker could exploit thi...Show more |
1Ibm 2Planning Analytics Cloud Planning Analytics LocalJun 17, 2026 May 17, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this...Show more |
1Wago 50852 0303 Firmware 0852 1305/000 001 Firmware0852 1305 Firmware+2 moreJun 17, 2026 May 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users. |
1Remotemouse 1Emote Remote Mouse Jun 17, 2026 May 7, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can retrieve recently used and running applications, their icons, and their file paths. This information is sent in cleartext and is not protected...Show more |
1Remotemouse 1Emote Remote Mouse Jun 17, 2026 May 7, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Emote Remote Mouse through 3.015. Attackers can close any running process by sending the process name in a specially crafted packet. This information is sent in cleartext and is not protected b...Show more |
1Remotemouse 1Emote Remote Mouse Jun 17, 2026 May 7, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can maximize or minimize the window of a running process by sending the process name in a crafted packet. This information is sent in cleartext and...Show more |
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive operations can be bypassed remotely by an authenticated attacker through requesting...Show more |
1Hp 1Edgeline Infrastructure Manager Jun 17, 2026 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited...Show more |
An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams from the doorbell. The binary app offers a web server on port 80 that all...Show more |
1Cisco 1Hyperflex Hx Data Platform Jun 17, 2026 May 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. This vulnerability is due to missing authen...Show more |
1Themegrill 1Themegrill Demo Importer Jun 17, 2026 May 5, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook. |
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface. This interface does not properly restrict access to internal functionality. Despite presenting a p...Show more |
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. The LS9 web interface provides functionality to access ADB over TCP. This is not enabled by default, b...Show more |
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Password Information Leak. The luci_service daemon running on port 7777 does not require authentication to...Show more |