CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-update POST request. Any attacker that can access the administrative inter...Show more |
A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to enable or disable MAC address filtering by submitting a crafted Forms/WlanMacFilter_1 POS...Show more |
A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to change DNS servers without being authenticated on the admin interface by submitting a cra...Show more |
A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to download the configuration (binary file) settings by submitting a rom-0 GET request witho...Show more |
1Redhat 2Enterprise Virtualization Enterprise Virtualization HypervisorNov 21, 2024 Feb 25, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run...Show more |
1Xerox 18Workcentre 3655 Firmware Workcentre 3655i FirmwareWorkcentre 5845 Firmware+15 moreJun 17, 2026 Feb 21, 2020 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected...Show more |
1Dell 174Chengming 3980 Firmware Embedded Box Pc 5000 FirmwareG3 3579 Firmware+171 moreJun 17, 2026 Feb 21, 2020 N/A· v4 5.3 MEDIUM· v3 2.1 LOW· v2 Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the s...Show more |
SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentication requests of the SAP Host Agent, leading to Denial of Service. |
1Bosch 3Divar Ip 2000 Firmware Divar Ip 5000 FirmwareVideo Streaming GatewayJun 17, 2026 Feb 7, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway. A success...Show more |
An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution . |
An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform privilege escalation through the lack of correct configuration in the server's sudoers file, which by de...Show more |
An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of the nmap -iL (aka input file) option. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Feb 6, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet. |
1Ibm 1Security Directory Server Jun 17, 2026 Feb 4, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 165953. |
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a reboot.cgi request. |
1Tp Link 1Tl Wr849n Firmware Jun 17, 2026 Jan 27, 2020 N/A· v4 6.1 MEDIUM· v3 4.1 MEDIUM· v2 TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI. |
11Ciktel CoshipFg Products+8 more18A3002ru Firmware A702r FirmwareEmta Ap Firmwre+15 moreJun 17, 2026 Jan 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TO...Show more |
A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a password-protected meeting without providing the meeting password. The c...Show more |
A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to download system log files from an affected device. The vulnerability is due to an issue in th...Show more |
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g....Show more |