← Back
CWE-306

2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,554)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Getigniteup
1Igniteup
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
1Getigniteup
1Igniteup
Jun 17, 2026
Nov 12, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.
1Gatech
1Computing For Good's Basic Laboratory Information System
Jun 17, 2026
Nov 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter sev...Show more
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter several facets of a user account, including promoting any user to an administrator.Show less
1Gatech
1Computing For Good's Basic Laboratory Information System
Jun 17, 2026
Nov 6, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may enumerate...Show more
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may enumerate the user names and facility names in use on a particular installation.Show less
1Gatech
1Computing For Good's Basic Laboratory Information System
Jun 17, 2026
Nov 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may change th...Show more
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may change the password of any administrator-level user.Show less
1Sillycycle
1Xlockmore
Nov 21, 2024
Nov 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.
1Sillycycle
1Xlockmore
Nov 21, 2024
Nov 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.
1Honeywell
48H2w2gr1 Firmware
H3w2gr1 FirmwareH3w2gr1v Firmware+45 more
Jun 17, 2026
Oct 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.
1Infosysta
1In App & Desktop Notifications
Jun 17, 2026
Oct 31, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obtain a list of all valid Jira usernames without authentication/authorization via the plugins/servlet/n...Show more
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obtain a list of all valid Jira usernames without authentication/authorization via the plugins/servlet/nfj/UserFilter?searchQuery=@ URI.Show less
1Infosysta
1In App & Desktop Notifications
Jun 17, 2026
Oct 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be...Show more
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be read without authentication/authorization. These notifications are then no longer displayed to the normal user.Show less
1Advantech
1Wise Paas/rmm
Jun 17, 2026
Oct 31, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.
1Ipswitch
1Moveit Transfer
Jun 17, 2026
Oct 31, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SF...Show more
In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL database is being used.Show less
1Mikrotik
1Routeros
Jun 17, 2026
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a server of the attacker's choice. The DNS...Show more
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a server of the attacker's choice. The DNS responses are cached by the router, potentially resulting in cache poisoningShow less
2Inea
Mitsubishielectric
2Me Rtu Firmware
Smartrtu Firmware
Jun 17, 2026
Oct 28, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download th...Show more
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).Show less
1Carel
1Pcoweb Firmware
Jun 17, 2026
Oct 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized con...Show more
Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning the cooling unit on and off and setting the temperature set point, can be modified without authentication.Show less
1Honeywell
1Ip Ak2 Firmware
Jun 17, 2026
Oct 25, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without authentication over...Show more
In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without authentication over the network.Show less
1Hinet
1Gpon Firmware
Jun 17, 2026
Oct 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HiNet GPON firmware version < I040GWR190731 allows an attacker login to device without any authentication.
1Dlink
1Dir 412 Firmware
Jun 17, 2026
Oct 16, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can clear the router's log file via act=clear&logtype=sysact to log_clear.php, which could be used to era...Show more
There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can clear the router's log file via act=clear&logtype=sysact to log_clear.php, which could be used to erase attack traces.Show less
1Cisco
1Identity Services Engine Software
Jun 17, 2026
Oct 16, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker read tcpdump files generated on an affected device. The vulnerability...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker read tcpdump files generated on an affected device. The vulnerability is due an issue in the authentication logic of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web interface. A successful exploit could allow the attacker to read a tcpdump file generated with a particular naming scheme.Show less
1Dlink
1Dir 412 Firmware
Jun 17, 2026
Oct 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via log_get.php, which could be used to discover the intranet network struc...Show more
There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via log_get.php, which could be used to discover the intranet network structure.Show less