← Back
CWE-306

3,081 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (3,081)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Universal Robots
1Ur Software
Jun 17, 2026
Apr 6, 2020
N/A· v4
9.4 CRITICAL· v3
9.0 HIGH· v2
Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server at port 29999 that allows for control ov...Show more
Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server at port 29999 that allows for control over core robot functions like starting/stopping programs, shutdown, reset safety and more. The DashBoard server is not protected by any kind of authentication or authorization.Show less
1Universal Robots
1Ur Software
Jun 17, 2026
Apr 6, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Data Exchange) interface on port 30004 which allows setting registers, the speed slider fraction as we...Show more
CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Data Exchange) interface on port 30004 which allows setting registers, the speed slider fraction as well as digital and analog Outputs. Additionally unautheticated reading of robot data is also possibleShow less
1Paessler
1Prtg Network Monitor
Jun 17, 2026
Apr 5, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP r...Show more
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.Show less
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
3.5 LOW· v3
3.5 LOW· v2
ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstate might thus not be noticed.
1Cacagoo
1Tv 288zd 2mp Firmware
Jun 17, 2026
Apr 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 allows access to the RTSP service without a password.
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Mar 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
1Unisoon
1Ultralog Express Firmware
Jun 17, 2026
Mar 27, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory.
1Teradici
1Pcoip Management Console
Jun 17, 2026
Mar 25, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default admin account. This vulnerability only exists when the default admin acco...Show more
Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default admin account. This vulnerability only exists when the default admin account is not disabled. It is fixed in 20.01.1 and 19.11.2.Show less
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. S-Voice leaks keyboard learned words via the lock screen. The Samsung ID is SVE-2018-12981 (February 2019).
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's learned words, and the clipboard contents, via the lock screen. The Samsung IDs are SVE-2018-12896, SVE-2018-12897 (May 2...Show more
An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's learned words, and the clipboard contents, via the lock screen. The Samsung IDs are SVE-2018-12896, SVE-2018-12897 (May 2019).Show less
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
An issue was discovered on Samsung mobile devices with P(9.0) software. Quick Panel allows enabling or disabling the Bluetooth stack without authentication. The Samsung ID is SVE-2019-14545 (July 2019).
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Gallery allows attackers to enable Location information sharing from the lock screen. The Samsung ID is SVE-2019-14462 (August 2...Show more
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Gallery allows attackers to enable Location information sharing from the lock screen. The Samsung ID is SVE-2019-14462 (August 2019).Show less
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery allows viewing of photos on the lock screen. The Samsung ID is SVE-2019-15055 (October 2019).
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October...Show more
An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).Show less
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Samsung mobile devices with Q(10.0) software. The DeX Lockscreen allows attackers to access the quick panel and notifications. The Samsung ID is SVE-2019-16532 (March 2020).
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can access the Developer options without authentication. The Samsung ID is SVE-2019-15800 (December 2019).
1Motorola
4Fx9500 41324d41 Us Firmware
Fx9500 41324d41 Ww FirmwareFx9500 81324d41 Us Firmware+1 more
Jun 17, 2026
Mar 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Motorola FX9500 devices allow remote attackers to read database files.
1Schneider Electric
1Interactive Graphical Scada System
Jun 17, 2026
Mar 23, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that otherwise require escal...Show more
A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that otherwise require escalation privileges when sending local network commands to the IGSS Update Service.Show less
1Artica
1Pandora Fms
Jun 17, 2026
Mar 23, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.
1Hom.ee
1Brain Cube Core
Jun 17, 2026
Mar 20, 2020
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal UART interface.