CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Epikur before 20.1.1. A Glassfish 4.1 server with a default configuration is running on TCP port 4848. No password is required to access it with the administrator account. |
1Hcltechsw 1Onetest Performance Jun 17, 2026 Feb 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources. |
1Rainbowfishsoftware 1Pacsone Server Jun 17, 2026 Feb 3, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges. |
1Mofinetwork 1Mofi4500 4gxelte Firmware Jun 17, 2026 Feb 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in a QR encoded picture that an unauthenticated adversary can download via the web-management interface...Show more |
1Mofinetwork 1Mofi4500 4gxelte Firmware Jun 17, 2026 Feb 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as cleartext credentials and password hashe...Show more |
HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method. |
1Proofpoint 1Insider Threat Management Jun 17, 2026 Jan 26, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveIT) Agent for Windows before 7.4.3, 7.5.4, 7.6.5, 7.7.5, 7.8.4, 7.9.3, 7.10.2, an...Show more |
1Newbee Mall Project 1Newbee Mall Jun 17, 2026 Jan 26, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginIntercepto...Show more |
1Ibm 1Security Identity Governance And Intelligence Jun 17, 2026 Jan 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. IBM X-Force ID: 192209. |
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions. |
Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vulnerability A vulnerability in the web management interface of Cisco Finesse, Cisco Virtualized V...Show more |
There is a missing authentication vulnerability in some Huawei smartphone.Successful exploitation of this vulnerability may lead to low-sensitive information exposure. |
1Siemens 65Scalance X200 4pirt Firmware Scalance X201 3pirt FirmwareScalance X202 2irt Firmware+62 moreJun 17, 2026 Jan 12, 2021 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0). The vulnerabil...Show more |
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access. IBM X-Force ID: 193...Show more |
The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication. |
1Expresstech 1Quiz And Survey Master Jun 17, 2026 Jan 1, 2021 N/A· v4 9.9 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an atta...Show more |
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API com...Show more |
1Huawei 1Imanager Neteco 6000 Jun 17, 2026 Dec 29, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 There is an information leak vulnerability in iManager NetEco 6000 versions V600R021C00. A module is lack of authentication. Attackers without access to the module can exploit this vulnerability to obtain extra informati...Show more |
An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts are also accessible: _internal/pc/abort.php...Show more |
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attacker to assign a static IP address that was once used by a valid user. |