CWE-306
3,068 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (3,068)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Redhat Theforeman2Foreman Tasks SatelliteJun 17, 2026 Jul 31, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an un...Show more |
Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time. |
2Amcrest Dahua12Dh Ipc Hx863x Dh Ipc Hx883xDh Sd4xxxxx+9 moreJun 17, 2026 Jul 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R,...Show more |
1Chinamobileltd 1Gpn2.4p21 C Cn Firmware Jun 17, 2026 Jul 19, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's are vulnerable to an unauthenticated remote reboot due. The component i...Show more |
1Rangerstudio 1Directus 7 Api Jun 17, 2026 Jul 19, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php. |
1Siemens 2Sinetplan Tia AdministratorJun 17, 2026 Jul 11, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration web application (TIA Administrator) allows to execute certain application commands without proper auth...Show more |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeov...Show more |
1Eq 3 2Ccu2 Firmware Ccu3 FirmwareJun 17, 2026 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID via the user authentication dialogue, aka HM...Show more |
1Eq 3 2Ccu2 Firmware Ccu3 FirmwareJun 17, 2026 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID via an invalid login attempt to the RemoteAp...Show more |
In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even...Show more |
Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all claim details by visiting easily guessable dashboard/uploads/claim_files/claim_id_ URLs. |
Lack of authentication in case-exporting components in DDRT Dashcom Live through 2019-05-08 allows anyone to remotely access all claim details by visiting easily guessable exportpdf/all_claim_detail.php?claim_id= URLs. |
hide.me before 2.4.4 on macOS suffers from a privilege escalation vulnerability in the connectWithExecutablePath:configFilePath:configFileName method of the me_hide_vpnhelper.Helper class in the me.hide.vpnhelper macOS p...Show more |
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if...Show more |
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE. |
1Ibm 1Robotic Process Automation With Automation Anywhere Jun 17, 2026 Jul 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in Ignite nodes. IBM X-Force ID: 161412. |
1Cylan 2Clever Dog Smart Camera Panorama Dog 2w Firmware Clever Dog Smart Camera Plus Dog 2w V4 FirmwareJun 17, 2026 Jun 20, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal SD card via the HTTP service on port 8000. The HTTP web server on the ca...Show more |
1Cisco 3Rv110w Firmware Rv130w FirmwareRv215w FirmwareJun 17, 2026 Jun 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to disconnect clients that are connected to the guest network on an affect...Show more |
1Cisco 1Wide Area Application Services Jun 17, 2026 Jun 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the HTTPS proxy feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to use the Central Manager as an HTTPS proxy. The vulnerability is due to...Show more |
1Cisco 2Integrated Management Controller Unified Computing SystemJun 17, 2026 Jun 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerab...Show more |