CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Automationdirect 1C More Hmi Ea9 Firmware Jun 17, 2026 Jul 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specif...Show more |
1Automationdirect 1C More Hmi Ea9 Firmware Jun 17, 2026 Jul 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. Th...Show more |
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utilized by an attacker to...Show more |
1Rockwellautomation 1Factorytalk View Jun 17, 2026 Jul 20, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissio...Show more |
Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files. |
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request. |
Advantech iView, versions 5.6 and prior, has an improper authentication for critical function (CWE-306) issue. Successful exploitation of this vulnerability may allow an attacker to obtain the information of the user tab...Show more |
1Dell 2Emc Omimssc For Sccm Emc Omimssc For ScvmmJun 17, 2026 Jul 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit...Show more |
1Siemens 3Sicam Mmu Firmware Sicam Sgu FirmwareSicam T FirmwareJun 17, 2026 Jul 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with access to the network could be able to install specially crafted firmwar...Show more |
1Siemens 3Sicam Mmu Firmware Sicam Sgu FirmwareSicam T FirmwareJun 17, 2026 Jul 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with access to the device's web server might be able to execute administrativ...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jul 14, 2020 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform...Show more |
1Dronecode 1Micro Air Vehicle Link Jun 17, 2026 Jul 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety of attacks including identity spoofing, unauthorized access, PITM attack...Show more |
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection woul...Show more |
1Cisco 1Unified Customer Voice Portal Jun 17, 2026 Jul 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The...Show more |
openSIS through 7.4 has Incorrect Access Control. |
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests. |
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests. |
Xiaomi router R3600 ROM before 1.0.50 is affected by a sensitive information leakage caused by an insecure interface get_config_result without authentication |
4Aliasrobotics Enabled RoboticsMobile Industrial Robotics+1 more10Er Flex Firmware Er Lite FirmwareEr One Firmware+7 moreJun 17, 2026 Jun 24, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers with access to the internal wireless an...Show more |
2Apache Oracle2Business Intelligence SparkJun 17, 2026 Jun 23, 2020 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master...Show more |