CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,344 vulnerabilities with CWE-306
CVE-2026-23693
CRITICAL
ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp API Proxy Abuse
CVSS 10.0
CVE-2026-27471
CRITICAL
ERP <=15.98.0/16.0.0-rc.1-16.6.0 - Auth Bypass
CVSS 9.1
CVE-2026-26048
HIGH
USR-W610 < 3.1.1.0 - Unauthenticated Denial of Service via Forged Management Frames
CVSS 7.5
CVE-2026-24790
HIGH
Welker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller - Unauthenticated Remote PLC Manipulation
CVSS 8.2
CVE-2026-26319
HIGH
OpenClaw < 2026.2.14 - Unauthenticated Webhook Spoofing via Missing Telnyx Signature Verification
CVSS 7.5
CVE-2026-27182
HIGH
Saturn Remote Mouse Server - Command Injection
CVSS 8.4
CVE-2026-1670
CRITICAL
Affected Products - Info Disclosure
CVSS 9.8
CVE-2026-2577
CRITICAL
Nanobot WhatsApp Bridge - Auth Bypass
CVSS 10.0
CVE-2026-26333
CRITICAL
Calero VeraSMART <2022 R1 - Unauthenticated Code Injection
CVSS 9.8
CVE-2026-26190
CRITICAL
Milvus < 2.5.27 - Unauthenticated API Access via Exposed TCP Port
CVSS 9.8
CVE-2026-26055
HIGH
Yoke <= 0.19.0 - Unauthenticated WASM Module Execution via ATC Webhook Endpoint
CVSS 7.5
CVE-2026-26235
HIGH
JUNG Smart Visu Server 1.1.1050 - DoS
CVSS 7.5
CVE-2026-1729
CRITICAL
AdForest theme <6.0.12 - Auth Bypass
CVSS 9.8
CVE-2026-25084
CRITICAL
ZLAN5143D >=v1.600 - Unauthenticated Critical Function Access via Direct URL Access
CVSS 9.8
CVE-2026-24789
CRITICAL
ZLAN5143D - Unauthenticated Password Change via Unprotected API Endpoint
CVSS 9.8
CVE-2026-2249
CRITICAL
METIS DFS <oscore 2.1.234-r18 - RCE
CVSS 9.8
CVE-2026-2248
CRITICAL
METIS WIC <= oscore 2.1.234-r18 - RCE
CVSS 9.8
CVE-2026-1603
HIGH
KEV
Ivanti Endpoint Manager < 2024 SU5 - Unauthenticated Credential Data Leak
CVSS 8.6
CVE-2026-25938
CRITICAL
FUXA 1.2.8-1.2.10 - Unauthenticated Remote Code Execution via Node-RED Plugin
CVSS 9.8
CVE-2026-25895
CRITICAL
FUXA < 1.2.10 - Unauthenticated Path Traversal and Arbitrary File Write
CVSS 9.8
CVE-2026-25885
HIGH
PolarLearn 0-PRERELEASE-16 - Unauthenticated Group Chat Access via WebSocket
CVSS 7.5
CVE-2026-25878
MEDIUM
frosh/adminer-platform < 2.2.1 - Unauthenticated Access to Adminer UI
CVSS 5.3
CVE-2026-25791
HIGH
Sliver < 1.7.0 - Unauthenticated Memory Exhaustion via DNS C2 Listener Session Allocation
CVSS 7.5
CVE-2026-25848
CRITICAL
JetBrains Hub <2025.3.119807 - Auth Bypass
CVSS 9.1
CVE-2026-2234
CRITICAL
HGiga C&Cm@il package olln-base < 7.0-978 - Unauthenticated Mail Content Access and Modification
CVSS 9.1
Details
Vulnerabilities
2,344
Exploit Likelihood
High