← Back
CWE-306

2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,554)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Couchbase
1Couchbase Server
Jun 17, 2026
Sep 10, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" wer...Show more
In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" were changed to only allow access by authenticated users with sufficient authorization. However, users were allowed unauthenticated and unauthorized access to the "default" bucket if the properties of this bucket were edited. This has been fixed in versions 5.1.0 and 5.5.0.Show less
1Couchbase
1Couchbase Server
Jun 17, 2026
Sep 10, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in...Show more
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access.Show less
1Supervisord
1Supervisor
Jun 17, 2026
Sep 10, 2019
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enable...Show more
In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentationShow less
1Lifterlms
1Lifterlms
Jun 17, 2026
Sep 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could le...Show more
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.Show less
1Search Exclude Project
1Search Exclude
Jun 17, 2026
Sep 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.
1Librenms
1Librenms
Jun 17, 2026
Sep 9, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functi...Show more
An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functions that are of a sensitive nature and are not expected to be publicly accessible.Show less
1Sahipro
1Sahi Pro
Jun 17, 2026
Sep 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the...Show more
An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the remote Sahi Pro server. There is also a password-protected web interface intended for remote access to scripts. This web interface lacks server-side validation, which allows an attacker to create/modify/delete a script remotely without any password. Chaining both of these issues results in remote code execution on the Sahi Pro server.Show less
1Grafana
1Grafana
Jun 17, 2026
Sep 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
1Webcraftic
1Woody Ad Snippets
Jun 17, 2026
Sep 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
1Restaurant Reservations Project
1Restaurant Reservations
Jun 17, 2026
Aug 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
1Androvideo
1Vd 1 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication.
1Androvideo
1Vd 1 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then tak...Show more
A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining software.Show less
1Asus
1Smarthome
Jun 17, 2026
Aug 29, 2019
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices tha...Show more
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices that connect with its gateway (HG100) via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).Show less
1Asus
1Hg100 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
8.1 HIGH· v3
4.8 MEDIUM· v2
A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol...Show more
A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).Show less
1Lexmark
25Cs31x Firmware
Cs41x FirmwareCx310 Firmware+22 more
Jun 17, 2026
Aug 28, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Various Lexmark products have Incorrect Access Control (issue 2 of 2).
1Lexmark
25Cs31x Firmware
Cs41x FirmwareCx310 Firmware+22 more
Jun 17, 2026
Aug 28, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Various Lexmark products have Incorrect Access Control (issue 1 of 2).
1Kaseya
1Virtual System Administrator
Jun 17, 2026
Aug 26, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An unauthenticated attacker can send properly formatted requests to the web a...Show more
An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An unauthenticated attacker can send properly formatted requests to the web application and download sensitive files and information. For example, the /DATAREPORTS directory can be farmed for reports. Because this directory contains the results of reports such as NMAP, Patch Status, and Active Directory domain metadata, an attacker can easily collect this critical information and parse it for information. There are a number of directories affected.Show less
1Sphinxsearch
1Sphinx
Jun 17, 2026
Aug 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).
1Cisco
3Integrated Management Controller Supervisor
Ucs DirectorUcs Director Express For Big Data
Jun 17, 2026
Aug 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote att...Show more
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a missing authentication check in an API call. An attacker who can send a request to an affected system could cause all currently authenticated users to be logged off. Repeated exploitation could cause the inability to maintain a session in the web-based management portal.Show less
1Humanica
1Humatrix 7
Jun 17, 2026
Aug 18, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file nam...Show more
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/photo/[file_name] URI.Show less