CWE-306
3,081 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (3,081)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Alcatelmobile 1Cingular Flip 2 Firmware Jun 17, 2026 Nov 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the...Show more |
An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to...Show more |
1Philips 1Taolight Smart Wi Fi Wiz Connected Led Bulb 9290022656 Firmware Jun 17, 2026 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness...Show more |
2Eq 3 Hm Print Project3Hm Print Homematic Ccu2 FirmwareHomematic Ccu3 FirmwareJun 17, 2026 Nov 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi and exec1.cgi scripts...Show more |
2Eq 3 Hm Email Project3Hm Email Homematic Ccu2 FirmwareHomematic Ccu3 FirmwareJun 17, 2026 Nov 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload u...Show more |
2Eq 3 Scriptparser Project3Homematic Ccu2 Firmware Homematic Ccu3 FirmwareScriptparserJun 17, 2026 Nov 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi script, which exe...Show more |
Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication. |
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure. |
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion. |
1Gatech 1Computing For Good's Basic Laboratory Information System Jun 17, 2026 Nov 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter sev...Show more |
1Gatech 1Computing For Good's Basic Laboratory Information System Jun 17, 2026 Nov 6, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may enumerate...Show more |
1Gatech 1Computing For Good's Basic Laboratory Information System Jun 17, 2026 Nov 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may change th...Show more |
xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window. |
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session. |
1Honeywell 48H2w2gr1 Firmware H3w2gr1 FirmwareH3w2gr1v Firmware+45 moreJun 17, 2026 Oct 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP. |
1Infosysta 1In App & Desktop Notifications Jun 17, 2026 Oct 31, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obtain a list of all valid Jira usernames without authentication/authorization via the plugins/servlet/n...Show more |
1Infosysta 1In App & Desktop Notifications Jun 17, 2026 Oct 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be...Show more |
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication. |
1Ipswitch 1Moveit Transfer Jun 17, 2026 Oct 31, 2019 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SF...Show more |
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a server of the attacker's choice. The DNS...Show more |