← Back
CWE-306

2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,554)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
2Sinvr 3 Central Control Server
Sinvr 3 Video Server
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVMS/SiNVR Video Server contains an authentication bypass vulnerability, even when...Show more
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVMS/SiNVR Video Server contains an authentication bypass vulnerability, even when properly configured with enforced authentication. A remote attacker with network access to the Video Server could exploit this vulnerability to read the SiVMS/SiNVR users database, including the passwords of all users in obfuscated cleartext.Show less
1Siemens
1Sppa T3000 Ms3000 Migration Server
Jun 17, 2026
Dec 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted p...Show more
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent from CVE-2019-18310. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.Show less
1Siemens
1Sppa T3000 Application Server
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can use methods exp...Show more
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can use methods exposed via this interface to receive password hashes of other users and to change user passwords. Please note that an attacker needs to have access to the Application Highway in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.Show less
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Intesync Solismed 3.3sp has Incorrect Access Control.
1Ibm
1Smartcloud Analytics Log Analysis
Jun 17, 2026
Dec 10, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper installations due to missing authentication. IBM X-Force ID: 159518.
1Redhat
2Openstack
Openstack Essex
Nov 21, 2024
Dec 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
openstack-utils openstack-db has insecure password creation
2Opensuse
Shadowsocks
3Backports Sle
LeapShadowsocks Libev
Jun 17, 2026
Dec 3, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code executi...Show more
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.Show less
2Opensuse
Shadowsocks
3Backports
LeapShadowsocks Libev
Jun 17, 2026
Dec 3, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path...Show more
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.Show less
1Inateck
1Bcst 60 Firmware
Jun 17, 2026
Dec 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's comput...Show more
Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system is unattended. In this way, an attacker can remotely take control over the victim's computer that is operated with an affected receiver of this device.Show less
1Anviz
1Anviz Firmware
Jun 17, 2026
Dec 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Anviz access control devices allow remote attackers to issue commands without a password.
1Anviz
1Anviz Firmware
Jun 17, 2026
Dec 2, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this information without credentials via port tcp/5010.
1Anviz
1Anviz Firmware
Jun 17, 2026
Dec 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via port tcp/5010.
2Debian
Xscreensaver Project
2Debian Linux
Xscreensaver
Nov 21, 2024
Nov 27, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
1Alcatelmobile
1Cingular Flip 2 Firmware
Jun 17, 2026
Nov 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the...Show more
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the-air update settings. (This web API is normally used by the system application to trigger firmware updates via OmaService.js.)Show less
1Gog
1Galaxy
Jun 17, 2026
Nov 21, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to...Show more
An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected.Show less
1Philips
1Taolight Smart Wi Fi Wiz Connected Led Bulb 9290022656 Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness...Show more
On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use the control API. The only requirement is that the attacker have network access to the bulb.Show less
2Eq 3
Hm Print Project
3Hm Print
Homematic Ccu2 FirmwareHomematic Ccu3 Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi and exec1.cgi scripts...Show more
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi and exec1.cgi scripts, which execute TCL script content from an HTTP POST request.Show less
2Eq 3
Hm Email Project
3Hm Email
Homematic Ccu2 FirmwareHomematic Ccu3 Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload u...Show more
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload upload and the testtcl.cgi script for its execution.Show less
2Eq 3
Scriptparser Project
3Homematic Ccu2 Firmware
Homematic Ccu3 FirmwareScriptparser
Jun 17, 2026
Nov 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi script, which exe...Show more
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi script, which executes TCL script content from an HTTP POST request.Show less
1Systematic
1Iris Webforms
Jun 17, 2026
Nov 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.