CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Couchbase 1Couchbase Server Jun 17, 2026 Sep 10, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" wer...Show more |
1Couchbase 1Couchbase Server Jun 17, 2026 Sep 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in...Show more |
In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enable...Show more |
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could le...Show more |
1Search Exclude Project 1Search Exclude Jun 17, 2026 Sep 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes. |
An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functi...Show more |
An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the...Show more |
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana. |
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution. |
1Restaurant Reservations Project 1Restaurant Reservations Jun 17, 2026 Aug 30, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication. |
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication. |
A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then tak...Show more |
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices tha...Show more |
A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol...Show more |
1Lexmark 25Cs31x Firmware Cs41x FirmwareCx310 Firmware+22 moreJun 17, 2026 Aug 28, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Various Lexmark products have Incorrect Access Control (issue 2 of 2). |
1Lexmark 25Cs31x Firmware Cs41x FirmwareCx310 Firmware+22 moreJun 17, 2026 Aug 28, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Various Lexmark products have Incorrect Access Control (issue 1 of 2). |
1Kaseya 1Virtual System Administrator Jun 17, 2026 Aug 26, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An unauthenticated attacker can send properly formatted requests to the web a...Show more |
Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only). |
1Cisco 3Integrated Management Controller Supervisor Ucs DirectorUcs Director Express For Big DataJun 17, 2026 Aug 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote att...Show more |
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file nam...Show more |