CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE. |
1Ibm 1Robotic Process Automation With Automation Anywhere Jun 17, 2026 Jul 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in Ignite nodes. IBM X-Force ID: 161412. |
1Cylan 2Clever Dog Smart Camera Panorama Dog 2w Firmware Clever Dog Smart Camera Plus Dog 2w V4 FirmwareJun 17, 2026 Jun 20, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal SD card via the HTTP service on port 8000. The HTTP web server on the ca...Show more |
1Cisco 3Rv110w Firmware Rv130w FirmwareRv215w FirmwareJun 17, 2026 Jun 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to disconnect clients that are connected to the guest network on an affect...Show more |
1Cisco 1Wide Area Application Services Jun 17, 2026 Jun 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the HTTPS proxy feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to use the Central Manager as an HTTPS proxy. The vulnerability is due to...Show more |
1Cisco 2Integrated Management Controller Unified Computing SystemJun 17, 2026 Jun 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerab...Show more |
1Cisco 2Integrated Management Controller Unified Computing SystemJun 17, 2026 Jun 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vu...Show more |
RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call. |
1Sap 1Netweaver Process Integration Jun 17, 2026 Jun 12, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. An attacker...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Jun 12, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive inform...Show more |
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfaces can obtain the WebUI login password without login, an attacker can exploit the vulnerability to o...Show more |
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled. |
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role...Show more |
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation. |
1Logitech 1R700 Laser Presentation Remote Firmware Jun 17, 2026 Jun 7, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keyst...Show more |
Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP1001 v1.3C is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's compute...Show more |
Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, do...Show more |
1Soyal 2Ar 727h Firmware Ar 829ev5 FirmwareJun 17, 2026 Jun 6, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST access. |
1Saet 2Tebe Small Firmware WebappJun 17, 2026 May 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of API calls without authentication, as demonstrated by retrieving password...Show more |
An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information. |