CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 May 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central Management Console without password in case of the BIPRWS application...Show more |
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption...Show more |
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control. |
1Wavlink 13Jetstream Ac3000 Firmware Jetstream Erac3000 FirmwareWl Wn575a3 Firmware+10 moreJun 17, 2026 May 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected...Show more |
1Wavlink 4Wn530hg4 Firmware Wn531g3 FirmwareWn533a8 Firmware+1 moreJun 17, 2026 May 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, inc...Show more |
1Wavlink 3Wn530hg4 Firmware Wn531g3 FirmwareWn572hg3 FirmwareJun 17, 2026 May 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentication is required in order to reach the page (a certain live_?.shtml pa...Show more |
Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration values via a crafted packet to UDP port 4800. NOTE: Moxa Service is an unauthenticated service that run...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the...Show more |
1Hitachienergy 1Microscada Pro Sys600 Jun 17, 2026 Apr 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function. |
TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files. |
1Inductiveautomation 1Ignition Gateway Jun 17, 2026 Apr 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition...Show more |
1Wavlink 15Jetstream Ac3000 Firmware Jetstream Erac3000 FirmwareWl Wn530hg4 Firmware+12 moreJun 17, 2026 Apr 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to...Show more |
1F5 1Big Iq Centralized Management Jun 17, 2026 Apr 24, 2020 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer. |
1Netgear 2Wac505 Firmware Wac510 FirmwareNov 21, 2024 Apr 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Certain NETGEAR devices are affected by authentication bypass. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17. |
An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted. |
2Abb Busch Jaeger26186/11 Firmware Tg/s3.2 FirmwareJun 17, 2026 Apr 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessing a specific uniform resource locator (U...Show more |
1Titan 1Sf Rush Smart Band Firmware Jun 17, 2026 Apr 22, 2020 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted....Show more |
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated URL. |
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltration of administrative credentials. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Apr 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call. |