← Back
CWE-306

3,081 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (3,081)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Honeywell
59H2w2pc1m Firmware
H2w2per3 FirmwareH2w4per3 Firmware+56 more
Jun 17, 2026
Sep 26, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Vi...Show more
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance IP Cameras: HBD3PR2,H4D3PRV3,HED3PR3,H4D3PRV2,HBD3PR1,H4W8PR2,HBW8PR2,H2W2PC1M,H2W4PER3,H2W2PER3,HEW2PER3,HEW4PER3B,HBW2PER1,HEW4PER2,HEW4PER2B,HEW2PER2,H4W2PER2,HBW2PER2,H4W2PER3, and HPW2P1. Affected Performance Series NVRs: HEN08104,HEN08144,HEN081124,HEN16104,HEN16144,HEN16184,HEN16204,HEN162244,HEN16284,HEN16304,HEN16384,HEN32104,HEN321124,HEN32204,HEN32284,HEN322164,HEN32304, HEN32384,HEN323164,HEN64204,HEN64304,HEN643164,HEN643324,HEN643484,HEN04103,HEN04113,HEN04123,HEN08103,HEN08113,HEN08123,HEN08143,HEN16103,HEN16123,HEN16143,HEN16163,HEN04103L,HEN08103L,HEN16103L,HEN32103L.Show less
1Gigastone
1Smart Battery A4 Firmware
Jun 17, 2026
Sep 25, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication.
1F5
1Big Iq Centralized Management
Jun 17, 2026
Sep 25, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS).
1Netapp
1Ontap Select Deploy Administration Utility
Jun 17, 2026
Sep 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote attackers to perform administrative actions.
1Publisure
1Publisure
Jun 17, 2026
Sep 18, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An issue was discovered in servletcontroller in the secure portal in Publisure 2.1.2. One can bypass authentication and perform a query on PHP forms within the /AdminDir folder that should be restricted.
1Eq 3
2Homematic Ccu2 Firmware
Homematic Ccu3 Firmware
Jun 17, 2026
Sep 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core proce...Show more
eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.Show less
1Atlassian
1Jira
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.
1Couchbase
1Couchbase Server
Jun 17, 2026
Sep 10, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" wer...Show more
In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" were changed to only allow access by authenticated users with sufficient authorization. However, users were allowed unauthenticated and unauthorized access to the "default" bucket if the properties of this bucket were edited. This has been fixed in versions 5.1.0 and 5.5.0.Show less
1Couchbase
1Couchbase Server
Jun 17, 2026
Sep 10, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in...Show more
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access.Show less
1Supervisord
1Supervisor
Jun 17, 2026
Sep 10, 2019
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enable...Show more
In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentationShow less
1Lifterlms
1Lifterlms
Jun 17, 2026
Sep 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could le...Show more
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.Show less
1Search Exclude Project
1Search Exclude
Jun 17, 2026
Sep 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.
1Librenms
1Librenms
Jun 17, 2026
Sep 9, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functi...Show more
An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functions that are of a sensitive nature and are not expected to be publicly accessible.Show less
1Sahipro
1Sahi Pro
Jun 17, 2026
Sep 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the...Show more
An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the remote Sahi Pro server. There is also a password-protected web interface intended for remote access to scripts. This web interface lacks server-side validation, which allows an attacker to create/modify/delete a script remotely without any password. Chaining both of these issues results in remote code execution on the Sahi Pro server.Show less
1Grafana
1Grafana
Jun 17, 2026
Sep 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
1Webcraftic
1Woody Ad Snippets
Jun 17, 2026
Sep 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
1Restaurant Reservations Project
1Restaurant Reservations
Jun 17, 2026
Aug 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
1Androvideo
1Vd 1 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication.
1Androvideo
1Vd 1 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then tak...Show more
A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining software.Show less
1Asus
1Smarthome
Jun 17, 2026
Aug 29, 2019
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices tha...Show more
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices that connect with its gateway (HG100) via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).Show less