CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,344 vulnerabilities with CWE-306
CVE-2026-23693 CRITICAL
ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp API Proxy Abuse
CVSS 10.0
CVE-2026-27471 CRITICAL
ERP <=15.98.0/16.0.0-rc.1-16.6.0 - Auth Bypass
CVSS 9.1
CVE-2026-26048 HIGH
USR-W610 < 3.1.1.0 - Unauthenticated Denial of Service via Forged Management Frames
CVSS 7.5
CVE-2026-24790 HIGH
Welker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller - Unauthenticated Remote PLC Manipulation
CVSS 8.2
CVE-2026-26319 HIGH
OpenClaw < 2026.2.14 - Unauthenticated Webhook Spoofing via Missing Telnyx Signature Verification
CVSS 7.5
CVE-2026-27182 HIGH
Saturn Remote Mouse Server - Command Injection
CVSS 8.4
CVE-2026-1670 CRITICAL
Affected Products - Info Disclosure
CVSS 9.8
CVE-2026-2577 CRITICAL
Nanobot WhatsApp Bridge - Auth Bypass
CVSS 10.0
CVE-2026-26333 CRITICAL
Calero VeraSMART <2022 R1 - Unauthenticated Code Injection
CVSS 9.8
CVE-2026-26190 CRITICAL
Milvus < 2.5.27 - Unauthenticated API Access via Exposed TCP Port
CVSS 9.8
CVE-2026-26055 HIGH
Yoke <= 0.19.0 - Unauthenticated WASM Module Execution via ATC Webhook Endpoint
CVSS 7.5
CVE-2026-26235 HIGH
JUNG Smart Visu Server 1.1.1050 - DoS
CVSS 7.5
CVE-2026-1729 CRITICAL
AdForest theme <6.0.12 - Auth Bypass
CVSS 9.8
CVE-2026-25084 CRITICAL
ZLAN5143D >=v1.600 - Unauthenticated Critical Function Access via Direct URL Access
CVSS 9.8
CVE-2026-24789 CRITICAL
ZLAN5143D - Unauthenticated Password Change via Unprotected API Endpoint
CVSS 9.8
CVE-2026-2249 CRITICAL
METIS DFS <oscore 2.1.234-r18 - RCE
CVSS 9.8
CVE-2026-2248 CRITICAL
METIS WIC <= oscore 2.1.234-r18 - RCE
CVSS 9.8
CVE-2026-1603 HIGH KEV
Ivanti Endpoint Manager < 2024 SU5 - Unauthenticated Credential Data Leak
CVSS 8.6
CVE-2026-25938 CRITICAL
FUXA 1.2.8-1.2.10 - Unauthenticated Remote Code Execution via Node-RED Plugin
CVSS 9.8
CVE-2026-25895 CRITICAL
FUXA < 1.2.10 - Unauthenticated Path Traversal and Arbitrary File Write
CVSS 9.8
CVE-2026-25885 HIGH
PolarLearn 0-PRERELEASE-16 - Unauthenticated Group Chat Access via WebSocket
CVSS 7.5
CVE-2026-25878 MEDIUM
frosh/adminer-platform < 2.2.1 - Unauthenticated Access to Adminer UI
CVSS 5.3
CVE-2026-25791 HIGH
Sliver < 1.7.0 - Unauthenticated Memory Exhaustion via DNS C2 Listener Session Allocation
CVSS 7.5
CVE-2026-25848 CRITICAL
JetBrains Hub <2025.3.119807 - Auth Bypass
CVSS 9.1
CVE-2026-2234 CRITICAL
HGiga C&Cm@il package olln-base < 7.0-978 - Unauthenticated Mail Content Access and Modification
CVSS 9.1
Details
Vulnerabilities 2,344
Exploit Likelihood High