CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,344 vulnerabilities with CWE-306
CVE-2026-20803 HIGH
Microsoft SQL Server 2022 and 2025 - Missing Authentication for Critical Function
CVSS 7.2
CVE-2026-0492 HIGH
SAP HANA Database - Privilege Escalation via User Switching
CVSS 8.8
CVE-2026-22812 HIGH
OpenCode <1.0.216 - Command Injection
CVSS 8.8
CVE-2026-22788 HIGH
wem-project/wem < 1.19 - Unauthenticated Sensitive Data Exposure and Limited Write Access via API Endpoints
CVSS 8.2
CVE-2026-0842 MEDIUM
Flycatcher Toys smART Sketcher <2.0 - Missing Authentication
CVSS 6.3
CVE-2026-0650 CRITICAL
OpenFlagr <= 1.1.18 - Unauthenticated Authentication Bypass via Path Normalization
CVE-2026-0625 CRITICAL
D-Link DSL/DIR/DNS - Unauthenticated DNS Configuration Modification via dnscfg.cgi Endpoint
CVE-2026-21446 CRITICAL
Bagisto 2.3.0-2.3.9 - Unauthenticated Admin Account Creation and Configuration Modification via Install API Endpoints
CVSS 9.8
CVE-2026-21445 CRITICAL
Langflow < 1.7.1 - Unauthenticated Sensitive Data Exposure and Destructive Operations via API Endpoints
CVSS 9.1
CVE-2025-71318 CRITICAL
NetMan 204 Missing Authentication for Administrative Functions
CVSS 9.8
CVE-2025-62619 MEDIUM
Amd Ryzen™ 4000 Series Mobile Processors With Radeon™ Graphics - Missing Authentication for Critical Function
CVE-2025-27853 HIGH
Garmin WDU v1 1.4.6 & v2 5.0 - Auth Bypass
CVSS 7.3
CVE-2025-13030 HIGH
django-mdeditor < 0.1.20 - Unauthenticated Arbitrary File Upload and Remote Code Execution via Image Upload Endpoint
CVSS 7.1
CVE-2025-53847 MEDIUM
Fortinet FortiOS <7.6.3 - Auth Bypass
CVSS 6.5
CVE-2025-30650 MEDIUM
Junos OS: Privileged local user can gain access to a Linux-based FPC as root
CVSS 6.7
CVE-2025-15620 HIGH
HiOS Switch Platform Denial-of-Service via Web Interface
CVSS 8.6
CVE-2025-67805 MEDIUM
Sage DPW 2025_06_004 - Info Disclosure
CVSS 5.9
CVE-2025-15517 HIGH
Authorization Bypass in HTTP Server Endpoints on TP-Link Archer NX200, NX210, NX500 and NX600
CVSS 8.1
CVE-2025-71257 HIGH
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass
CVSS 7.3
CVE-2025-15515 MEDIUM
vivo Easyshare <7.0.11.5 - Info Disclosure
CVSS 5.5
CVE-2025-13779 HIGH
ABB AWIN GW100 rev.2 & GW120 - Auth Bypass
CVSS 8.3
CVE-2025-13778 MEDIUM
ABB AWIN GW100 rev.2 & GW120 - Auth Bypass
CVSS 6.5
CVE-2025-30035 CRITICAL
CGM CLININET - Unauthenticated Authentication Bypass via Username
CVE-2025-15567 LOW
vivo health_module < 5.3.0.0 - Partial Information Disclosure
CVSS 3.3
CVE-2025-15509 MEDIUM
vivo smartremote_module < 5.1.2.0 - Information Disclosure via URL Loading
CVSS 4.3
Details
Vulnerabilities 2,344
Exploit Likelihood High