CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,344 vulnerabilities with CWE-306
CVE-2026-20803
HIGH
Microsoft SQL Server 2022 and 2025 - Missing Authentication for Critical Function
CVSS 7.2
CVE-2026-0492
HIGH
SAP HANA Database - Privilege Escalation via User Switching
CVSS 8.8
CVE-2026-22812
HIGH
OpenCode <1.0.216 - Command Injection
CVSS 8.8
CVE-2026-22788
HIGH
wem-project/wem < 1.19 - Unauthenticated Sensitive Data Exposure and Limited Write Access via API Endpoints
CVSS 8.2
CVE-2026-0842
MEDIUM
Flycatcher Toys smART Sketcher <2.0 - Missing Authentication
CVSS 6.3
CVE-2026-0650
CRITICAL
OpenFlagr <= 1.1.18 - Unauthenticated Authentication Bypass via Path Normalization
CVE-2026-0625
CRITICAL
D-Link DSL/DIR/DNS - Unauthenticated DNS Configuration Modification via dnscfg.cgi Endpoint
CVE-2026-21446
CRITICAL
Bagisto 2.3.0-2.3.9 - Unauthenticated Admin Account Creation and Configuration Modification via Install API Endpoints
CVSS 9.8
CVE-2026-21445
CRITICAL
Langflow < 1.7.1 - Unauthenticated Sensitive Data Exposure and Destructive Operations via API Endpoints
CVSS 9.1
CVE-2025-71318
CRITICAL
NetMan 204 Missing Authentication for Administrative Functions
CVSS 9.8
CVE-2025-62619
MEDIUM
Amd Ryzen™ 4000 Series Mobile Processors With Radeon™ Graphics - Missing Authentication for Critical Function
CVE-2025-27853
HIGH
Garmin WDU v1 1.4.6 & v2 5.0 - Auth Bypass
CVSS 7.3
CVE-2025-13030
HIGH
django-mdeditor < 0.1.20 - Unauthenticated Arbitrary File Upload and Remote Code Execution via Image Upload Endpoint
CVSS 7.1
CVE-2025-53847
MEDIUM
Fortinet FortiOS <7.6.3 - Auth Bypass
CVSS 6.5
CVE-2025-30650
MEDIUM
Junos OS: Privileged local user can gain access to a Linux-based FPC as root
CVSS 6.7
CVE-2025-15620
HIGH
HiOS Switch Platform Denial-of-Service via Web Interface
CVSS 8.6
CVE-2025-67805
MEDIUM
Sage DPW 2025_06_004 - Info Disclosure
CVSS 5.9
CVE-2025-15517
HIGH
Authorization Bypass in HTTP Server Endpoints on TP-Link Archer NX200, NX210, NX500 and NX600
CVSS 8.1
CVE-2025-71257
HIGH
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass
CVSS 7.3
CVE-2025-15515
MEDIUM
vivo Easyshare <7.0.11.5 - Info Disclosure
CVSS 5.5
CVE-2025-13779
HIGH
ABB AWIN GW100 rev.2 & GW120 - Auth Bypass
CVSS 8.3
CVE-2025-13778
MEDIUM
ABB AWIN GW100 rev.2 & GW120 - Auth Bypass
CVSS 6.5
CVE-2025-30035
CRITICAL
CGM CLININET - Unauthenticated Authentication Bypass via Username
CVE-2025-15567
LOW
vivo health_module < 5.3.0.0 - Partial Information Disclosure
CVSS 3.3
CVE-2025-15509
MEDIUM
vivo smartremote_module < 5.1.2.0 - Information Disclosure via URL Loading
CVSS 4.3
Details
Vulnerabilities
2,344
Exploit Likelihood
High