CWE-306
3,081 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (3,081)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.1 CRITICAL· v3 9.4 HIGH· v2 An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A spe...Show more |
1Dell 1Rsa Identity Governance And Lifecycle Jun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with...Show more |
1Wago 2Pfc 100 Firmware Pfc 200 FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.1 CRITICAL· v3 8.5 HIGH· v2 An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12). A...Show more |
The issue was addressed with improved UI handling. This issue is fixed in iOS 12.4, watchOS 5.3. A user may inadvertently complete an in-app purchase while on the lock screen. |
A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4. An encrypted volume may be unmounted and remounted by a different user without prompting for the password. |
1Shadowsocks 1Shadowsocks Libev Jun 17, 2026 Dec 18, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an...Show more |
2Petwant Skymee2Petalk Ai Firmware Pf 103 FirmwareJun 17, 2026 Dec 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate firmware upgrades and alter device settings. |
1Siemens 2Sinvr 3 Central Control Server Sinvr 3 Video ServerJun 17, 2026 Dec 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVMS/SiNVR Video Server contains an authentication bypass vulnerability, even when...Show more |
1Siemens 1Sppa T3000 Ms3000 Migration Server Jun 17, 2026 Dec 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted p...Show more |
1Siemens 1Sppa T3000 Application Server Jun 17, 2026 Dec 12, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminService is available without authentication on the Application Server. An attacker can use methods exp...Show more |
Intesync Solismed 3.3sp has Incorrect Access Control. |
1Ibm 1Smartcloud Analytics Log Analysis Jun 17, 2026 Dec 10, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper installations due to missing authentication. IBM X-Force ID: 159518. |
1Redhat 2Openstack Openstack EssexNov 21, 2024 Dec 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 openstack-utils openstack-db has insecure password creation |
2Opensuse Shadowsocks3Backports Sle LeapShadowsocks LibevJun 17, 2026 Dec 3, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code executi...Show more |
2Opensuse Shadowsocks3Backports LeapShadowsocks LibevJun 17, 2026 Dec 3, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path...Show more |
Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's comput...Show more |
Anviz access control devices allow remote attackers to issue commands without a password. |
Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this information without credentials via port tcp/5010. |
Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via port tcp/5010. |
2Debian Xscreensaver Project2Debian Linux XscreensaverNov 21, 2024 Nov 27, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication. |