CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,343 vulnerabilities with CWE-306
CVE-2026-12183
CRITICAL
Nefteprodukttekhnika LLC Buk Ts-g Gas Station Automation System < 2.10.2 - Improper Authentication
CVSS 9.8
CVE-2026-53868
HIGH
Capgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and Deletion
CVSS 7.5
CVE-2026-50287
HIGH
Missing Authentication for Critical Function in @agenticmail/mcp
CVE-2026-53981
HIGH
Cap-go < v12.128.2 Account Takeover via Unauthenticated Email Change Mechanism
CVSS 7.6
CVE-2026-50085
HIGH
Aqara Board IoT insecure debug API
CVSS 8.6
CVE-2026-50082
MEDIUM
Aqara Developer Portal insecure authentication token
CVSS 6.5
CVE-2026-8694
MEDIUM
Improper access control on the API documentation endpoint in PowerShell Universal
CVSS 5.3
CVE-2026-11848
MEDIUM
IEI Integration Corp| iRM-IEI Remote Management - Missing Authentication
CVSS 5.3
CVE-2026-11535
CRITICAL
Vivo PcSuite - Missing Authentication for Critical Function
CVE-2026-50245
HIGH
Brickcom Cameras Missing Authentication for Critical Function
CVSS 7.7
CVE-2026-49973
CRITICAL
Hermes WebUI < 0.51.358 Unauthenticated Password Takeover via /api/settings
CVSS 9.4
CVE-2026-35273
CRITICAL
KEV
PeopleSoft Enterprise PeopleTools 8.61-8.62 - Unauthenticated Remote Code Execution via Updates Environment Management
CVSS 9.8
CVE-2026-46612
HIGH
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
CVSS 8.8
CVE-2026-20253
CRITICAL
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
CVSS 9.8
CVE-2026-45567
HIGH
Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt
CVSS 8.3
CVE-2026-9045
HIGH
Lenovo Accessories And Display Manager For Enterprise < 1.0.9 - Missing Authentication for Critical Function
CVSS 7.8
CVE-2026-8335
HIGH
Aix-DB <= 1.2.4 - Missing Authentication on LLM SQL Query Endpoint
CVE-2026-53469
CRITICAL
Migration-planner: unprotected delete endpoint wipes all tenant data
CVSS 9.1
CVE-2026-50512
HIGH
Microsoft PC Manager Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-9212
MEDIUM
Insufficient authentication and input validation in certain NETGEAR products
CVE-2026-50507
MEDIUM
Microsoft Windows 10 Version 1607 - Windows BitLocker Security Feature Bypass Vulnerability
CVSS 6.8
CVE-2026-47281
CRITICAL
Visual Studio Code Elevation of Privilege Vulnerability
CVSS 9.6
CVE-2026-11429
CRITICAL
Path Traversal in Altium Git Service Allows Remote Code Execution
CVE-2026-11420
CRITICAL
Path Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write and File Read
CVE-2026-45327
HIGH
TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injection
CVSS 8.2
Details
Vulnerabilities
2,343
Exploit Likelihood
High