CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Gehealthcare 6Apexpro Telemetry Server Firmware Carescape Central Station Mai700 FirmwareCarescape Central Station Mas700 Firmware+3 moreJun 17, 2026 Jan 24, 2020 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Sta...Show more |
websitebaker prior to and including 2.8.1 has an authentication error in backup module. |
Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI. |
1Webfactoryltd 1Wp Database Reset Jun 17, 2026 Jan 16, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in tha...Show more |
1Siemens 7Scalance X 200rna Firmware Scalance X 300 FirmwareScalance X204rna Firmware+4 moreJun 17, 2026 Jan 16, 2020 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 A vulnerability has been identified in SCALANCE X204RNA (HSR), SCALANCE X204RNA (PRP), SCALANCE X204RNA EEC (HSR), SCALANCE X204RNA EEC (PRP), SCALANCE X204RNA EEC (PRP/HSR), SCALANCE X302-7 EEC (230V), SCALANCE X302-7 E...Show more |
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Control. |
1Bss Continuity Cms Project 1Bss Continuty Cms Nov 21, 2024 Jan 9, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability |
1Genexis 1Platinum 4410 Firmware Jun 17, 2026 Jan 8, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI. |
1Dlink 2Dcs 935l Firmware Dcs 960l FirmwareJun 17, 2026 Jan 7, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within t...Show more |
1Dten 2D5 Firmware D7 FirmwareJun 17, 2026 Jan 6, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 DTEN D5 and D7 before 1.3.2 devices allows remote attackers to read saved whiteboard image PDF documents via storage/emulated/0/Notes/PDF on TCP port 8080 without authentication. |
An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control. |
4Canonical DebianGnome+1 more4Debian Linux NetworkmanagerOpensuse+1 moreNov 21, 2024 Dec 26, 2019 N/A· v4 4.4 MEDIUM· v3 3.3 LOW· v2 In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network. |
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A si...Show more |
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.1 CRITICAL· v3 9.4 HIGH· v2 An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A spe...Show more |
1Dell 1Rsa Identity Governance And Lifecycle Jun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with...Show more |
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.1 CRITICAL· v3 8.5 HIGH· v2 An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12). A...Show more |
The issue was addressed with improved UI handling. This issue is fixed in iOS 12.4, watchOS 5.3. A user may inadvertently complete an in-app purchase while on the lock screen. |
A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4. An encrypted volume may be unmounted and remounted by a different user without prompting for the password. |
1Shadowsocks 1Shadowsocks Libev Jun 17, 2026 Dec 18, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an...Show more |
2Petwant Skymee2Petalk Ai Firmware Pf 103 FirmwareJun 17, 2026 Dec 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate firmware upgrades and alter device settings. |