CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication. This affects Apache...Show more |
D-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart, before MAC address filtering rules become active. |
HUAWEI P30 smart phone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. Due to improper authentication of specific interface, in specific scenario attackers could access...Show more |
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a specially crafted HTTP command to the remote server. IBM X-Force ID: 1...Show more |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Jun 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents. |
1Siemens 1Logo! 8 Bm Firmware Jun 17, 2026 Jun 10, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead to an attacker reading and modifying the device configuration and obtain project files from affected...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jun 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31...Show more |
1Inductiveautomation 1Ignition Gateway Jun 17, 2026 Jun 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensiti...Show more |
1Sony 11Wf 1000x Firmware Wf Sp700n FirmwareWh 1000xm2 Firmware+8 moreJun 17, 2026 Jun 9, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with firmware versions prior to 4.5.2 have vulnerability that someone withi...Show more |
2Fedoraproject Gnome2Fedora NetworkmanagerJun 17, 2026 Jun 8, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the...Show more |
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscreen feature does not block access to Quick Panel and notifications. The Samsung ID is SVE-2020-17187 (June 2020). |
An issue was discovered on Samsung mobile devices with Q(10.0) software. The Lockscreen feature does not block Quick Panel access to Music Share. The Samsung ID is SVE-2020-17145 (June 2020). |
1Cisco 2Application Policy Infrastructure Controller Application Services EngineJun 17, 2026 Jun 3, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive information of other users on an affected device. The vulnerability is due to...Show more |
1Cisco 2Application Policy Infrastructure Controller Application Services EngineJun 17, 2026 Jun 3, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on an affected device. The vulnerability is due to insufficient authentica...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jun 3, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution...Show more |
1Ge 3Rt430 Firmware Rt431 FirmwareRt434 FirmwareJun 17, 2026 Jun 2, 2020 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application could allow multiple unauthenticated attacks that could cause serious i...Show more |
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an attacker to obtain sensitive information...Show more |
CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_except_for_up`. It was meant as an extension to the long standing settin...Show more |
1Dlink 1Dap 1360 Revision F Firmware Jun 17, 2026 May 15, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented HTTP request. Although this is the primary vulnerability, the impact de...Show more |
Veritas APTARE versions prior to 10.4 allowed sensitive information to be accessible without authentication. |