CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Aug 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For ex...Show more |
1Eq 3 2Homematic Ccu2 Firmware Homematic Ccu3 FirmwareJun 17, 2026 Aug 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, resulting in the ability to read, set and deletion of Metadata. |
1Eq 3 2Homematic Ccu2 Firmware Homematic Ccu3 FirmwareJun 17, 2026 Aug 13, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because the undocumented addons/xmlapi/exec.cgi scrip...Show more |
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged...Show more |
1Cisco 1Enterprise Network Function Virtualization Infrastructure Jun 17, 2026 Aug 7, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of a...Show more |
2Apache Redhat3Activemq Jboss A MqJboss FuseNov 21, 2024 Aug 1, 2019 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service...Show more |
2Redhat Theforeman2Foreman Tasks SatelliteJun 17, 2026 Jul 31, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an un...Show more |
Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time. |
2Amcrest Dahua12Dh Ipc Hx863x Dh Ipc Hx883xDh Sd4xxxxx+9 moreJun 17, 2026 Jul 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R,...Show more |
1Chinamobileltd 1Gpn2.4p21 C Cn Firmware Jun 17, 2026 Jul 19, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's are vulnerable to an unauthenticated remote reboot due. The component i...Show more |
1Rangerstudio 1Directus 7 Api Jun 17, 2026 Jul 19, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php. |
1Siemens 2Sinetplan Tia AdministratorJun 17, 2026 Jul 11, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration web application (TIA Administrator) allows to execute certain application commands without proper auth...Show more |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeov...Show more |
1Eq 3 2Ccu2 Firmware Ccu3 FirmwareJun 17, 2026 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID via the user authentication dialogue, aka HM...Show more |
1Eq 3 2Ccu2 Firmware Ccu3 FirmwareJun 17, 2026 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID via an invalid login attempt to the RemoteAp...Show more |
In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even...Show more |
Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all claim details by visiting easily guessable dashboard/uploads/claim_files/claim_id_ URLs. |
Lack of authentication in case-exporting components in DDRT Dashcom Live through 2019-05-08 allows anyone to remotely access all claim details by visiting easily guessable exportpdf/all_claim_detail.php?claim_id= URLs. |
hide.me before 2.4.4 on macOS suffers from a privilege escalation vulnerability in the connectWithExecutablePath:configFilePath:configFileName method of the me_hide_vpnhelper.Helper class in the me.hide.vpnhelper macOS p...Show more |
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if...Show more |