CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Binom3 1Universal Multifunctional Electric Power Quality Meter Firmware May 13, 2026 Feb 13, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for remote service gives access to application set up and configuration. |
1Moxa 10Nport 5100 Series Firmware Nport 5100a Series FirmwareNport 5200 Series Firmware+7 moreJun 2, 2026 Feb 13, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series version...Show more |
1Sap 1Netweaver Application Server Java Apr 22, 2026 May 13, 2016 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as explo...Show more |
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists becaus...Show more |
1Schneider Electric 5Etg3000 Factorycast Hmi Gateway Firmware Tsxetg3000Tsxetg3010+2 moreMay 6, 2026 Jan 27, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and confi...Show more |
1Phoenixcontact Software 2Multiprog Proconos EclrMay 6, 2026 Jan 17, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic. |
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via...Show more |
1Siemens 1Ruggedcom Rugged Operating System May 6, 2026 Apr 1, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted...Show more |
The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a craf...Show more |
1Symantec 1Altiris Deployment Solution Apr 23, 2026 Jun 8, 2009 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a "Shatter" style attack...Show more |
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_...Show more |
3Canonical DebianMit3Debian Linux Kerberos 5Ubuntu LinuxApr 23, 2026 Apr 6, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882. |
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message...Show more |
D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and read the config.img file, which contains sensitive information such as the administrative password,...Show more |