CWE-306
3,081 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (3,081)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Honeywell 59H2w2pc1m Firmware H2w2per3 FirmwareH2w4per3 Firmware+56 moreJun 17, 2026 Sep 26, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Vi...Show more |
1Gigastone 1Smart Battery A4 Firmware Jun 17, 2026 Sep 25, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication. |
1F5 1Big Iq Centralized Management Jun 17, 2026 Sep 25, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS). |
1Netapp 1Ontap Select Deploy Administration Utility Jun 17, 2026 Sep 24, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote attackers to perform administrative actions. |
An issue was discovered in servletcontroller in the secure portal in Publisure 2.1.2. One can bypass authentication and perform a query on PHP forms within the /AdminDir folder that should be restricted. |
1Eq 3 2Homematic Ccu2 Firmware Homematic Ccu3 FirmwareJun 17, 2026 Sep 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core proce...Show more |
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability. |
1Couchbase 1Couchbase Server Jun 17, 2026 Sep 10, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" wer...Show more |
1Couchbase 1Couchbase Server Jun 17, 2026 Sep 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in...Show more |
In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enable...Show more |
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could le...Show more |
1Search Exclude Project 1Search Exclude Jun 17, 2026 Sep 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes. |
An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functi...Show more |
An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the...Show more |
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana. |
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution. |
1Restaurant Reservations Project 1Restaurant Reservations Jun 17, 2026 Aug 30, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication. |
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication. |
A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then tak...Show more |
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices tha...Show more |