CWE-306
3,066 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (3,066)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncat...Show more |
1Humaxdigital 1Hg100r Firmware May 13, 2026 Jul 4, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router credentials are stored in plaintext inside the backup, aka GatewaySettings....Show more |
1Sierra Wireless 2Airlink Raven Xe Firmware Airlink Raven Xt FirmwareMay 13, 2026 Jun 30, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without...Show more |
5Greenpacket HuaweiMada+2 more14Bm2022 Firmware Hes 309m FirmwareHes 319m2w Firmware+11 moreMay 13, 2026 Jun 20, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by perform...Show more |
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of...Show more |
In all Android releases from CAF using the Linux kernel, the Hypervisor API could be misused to bypass authentication. |
1Sony 3Pcs Xc1 Firmware Pcs Xg100 FirmwarePcs Xg77 FirmwareMay 13, 2026 Jun 9, 2017 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices with firmware version prior to Ver.1.22 allow an attacker on the same network se...Show more |
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port 4000. |
1Summerinfant 1Baby Zoom Wifi Monitor Firmware May 13, 2026 Apr 10, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to bypass authentication, related to the MySnapCam web service. |
1Cisco 2Asr 5000 Series Software Virtualized Packet CoreMay 13, 2026 Mar 15, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR 5000 Series, ASR 5500 Series, ASR 5700 Series devices, and Cisco Virtualized Packet Core could allow a...Show more |
1Veritas 2Netbackup Netbackup ApplianceMay 13, 2026 Mar 2, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Unauthenticated CORBA interfaces permit inappropriate access. |
1Smiths Medical 1Cadd Solis Medication Safety Software May 13, 2026 Feb 13, 2017 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. CADD-Solis Medication Safety Software grants an authenticated user elevated privileges on the SQL database,...Show more |
1Binom3 1Universal Multifunctional Electric Power Quality Meter Firmware May 13, 2026 Feb 13, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for remote service gives access to application set up and configuration. |
1Moxa 10Nport 5100 Series Firmware Nport 5100a Series FirmwareNport 5200 Series Firmware+7 moreJun 2, 2026 Feb 13, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series version...Show more |
1Sap 1Netweaver Application Server Java Apr 22, 2026 May 13, 2016 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as explo...Show more |
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists becaus...Show more |
1Schneider Electric 5Etg3000 Factorycast Hmi Gateway Firmware Tsxetg3000Tsxetg3010+2 moreMay 6, 2026 Jan 27, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and confi...Show more |
1Phoenixcontact Software 2Multiprog Proconos EclrMay 6, 2026 Jan 17, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic. |
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via...Show more |
1Siemens 1Ruggedcom Rugged Operating System May 6, 2026 Apr 1, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted...Show more |