CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Information Leak. The luci_service deamon running on port 7777 provides a sub-category of commands for...Show more |
Dell Hybrid Client versions prior to 1.5 contain a missing authentication for a critical function vulnerability. A local unauthenticated attacker may exploit this vulnerability in order to gain root level access to the s...Show more |
1Smartwares 1Home Easy Firmware Jun 17, 2026 Apr 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Smartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vulnerability. An attacker could disclose sensitive and clear-text information resulting in authenticat...Show more |
1Ave 753ab Wbs Firmware DominaplusTs01 Firmware+4 moreJun 17, 2026 Apr 28, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to cause a denial of service scenario. |
1Meritlilin 41P2g1022 Firmware P2g1022x FirmwareP2g1052 Firmware+38 moreJun 17, 2026 Apr 28, 2021 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices. |
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the da...Show more |
The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets through a curl command or an unauthentica...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraOpenvpn+1 moreJun 17, 2026 Apr 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further i...Show more |
Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to login to the device as an authenticated user without the access privilege via unspecified vectors. |
1Fibaro 2Home Center 2 Firmware Home Center Lite FirmwareJun 17, 2026 Apr 19, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API endpoints could be accessed without authentication to trigger a shutdo...Show more |
1Thrivethemes 20Focusblog IgnitionLuxe+17 moreJun 17, 2026 Apr 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ulti...Show more |
VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts. |
1Cohesity 1Cohesity Dataplatform Jun 17, 2026 Apr 2, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A man-in-the-middle vulnerability in Cohesity DataPlatform support channel in version 6.3 up to 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. Missing server authentication in impacted versions can allow an attacker...Show more |
1F5 1Big Iq Centralized Management Jun 17, 2026 Mar 31, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authentication for the clustering transport services, and all data used by ElasticSearch for transport is unenc...Show more |
1F5 1Big Iq Centralized Management Jun 17, 2026 Mar 31, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ high availability (HA) when using a Quorum device for automatic failover does not implement any form of authentication with the Corosync daemon. Note: Software version...Show more |
1Grandstream 7Grp2612 Firmware Grp2612p FirmwareGrp2612w Firmware+4 moreJun 17, 2026 Mar 29, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface. |
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unl...Show more |
1Zyxel 3Lte4506 M606 Firmware Lte7460 M608 FirmwareWah7706 FirmwareJun 17, 2026 Mar 16, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provi...Show more |
1Netgear 2Gs116e Firmware Jgs516pe FirmwareJun 17, 2026 Mar 10, 2021 N/A· v4 7.1 HIGH· v3 4.8 MEDIUM· v2 NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write request command. |
1Emerson 1Smart Wireless Gateway 1420 Firmware Jun 17, 2026 Mar 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device information from the administrator console without authentication. |