CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,344 vulnerabilities with CWE-306
CVE-2025-12447 MEDIUM
Google Chrome < 142.0.7444.59 - UI Spoofing via Omnibox Security UI
CVSS 4.2
CVE-2025-12444 MEDIUM
Google Chrome < 142.0.7444.59 - UI Spoofing via Fullscreen Security UI
CVSS 4.2
CVE-2025-12436 MEDIUM
Google Chrome < 142.0.7444.59 - Policy Bypass in Extensions
CVSS 5.9
CVE-2025-20358 CRITICAL
Cisco Unified Contact Center Express - Unauthenticated Remote Code Execution via Authentication Bypass
CVSS 9.4
CVE-2025-55108 CRITICAL
BMC Control-M/Agent 9.0.18-9.0.22 - Unauthenticated Remote Code Execution and Arbitrary File Read/Write
CVSS 10.0
CVE-2025-12108 CRITICAL
Survision LPR Camera - Info Disclosure
CVE-2025-61956 CRITICAL
Radiometrics VizAir < 2025-08 - Unauthenticated Critical Function Access
CVSS 10.0
CVE-2025-61945 CRITICAL
Radiometrics VizAir < 2025-08 - Unauthenticated Admin Panel Access
CVSS 10.0
CVE-2025-47357 HIGH
Qualcomm Firmware - Unauthenticated Information Disclosure via QFPROM Fuse Region Access
CVSS 8.0
CVE-2025-11007 CRITICAL
CE21 Suite 2.2.1-2.3.1 - Unauthenticated Plugin Settings Update via wp_ajax_nopriv_ce21_single_sign_on_save_api_settings
CVSS 9.8
CVE-2025-8558 MEDIUM
Proofpoint Insider Threat Management Server < 7.17.2 - Unauthenticated Agent Unregistration via Adjacent Network
CVSS 5.4
CVE-2025-48397 HIGH
Eaton BLSS <7.3.0.SCP004 - Auth Bypass
CVSS 7.1
CVE-2025-52665 CRITICAL
UniFi Access 3.3.22-3.4.31 - Unauthenticated Management API Exposure
CVSS 10.0
CVE-2025-12477 CRITICAL
BLU-IC2 and BLU-IC4 < 1.20 - Server Version Disclosure
CVSS 9.8
CVE-2025-12476 CRITICAL
BLU-IC2 and BLU-IC4 Firmware < 1.20 - Unauthenticated Access to Critical Function
CVSS 9.8
CVE-2025-41090 HIGH
microCLAUDIA <3.2.0 - Privilege Escalation
CVE-2025-43994 HIGH
Dell Storage Manager 20.1.21 - Unauthenticated Information Disclosure
CVSS 8.6
CVE-2025-62607 MEDIUM
nautobot-ssot < 3.10.0 - Unauthenticated Information Disclosure via Configuration Page
CVSS 5.3
CVE-2025-41110 HIGH
Ghost Robotics Vision 60 v0.27.2 - Improper Authentication via Hardcoded WiFi and SSH Credentials
CVSS 8.8
CVE-2025-61756 HIGH
Oracle Financial Services Analytical ... - Missing Authentication
CVSS 7.5
CVE-2025-62481 CRITICAL
Oracle Marketing 12.2.3-12.2.14 - Unauthenticated Authentication Bypass in Marketing Administration
CVSS 9.8
CVE-2025-62287 MEDIUM
Oracle Life Sciences InForm 7.0.1.0 - Unauthenticated Data Manipulation and Read Access via Web Server
CVSS 6.1
CVE-2025-61757 CRITICAL KEV
Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Code Execution via REST WebServices
CVSS 9.8
CVE-2025-61752 HIGH
Oracle WebLogic Server 14.1.1.0.0 and 14.1.2.0.0 - Unauthenticated Denial of Service via HTTP/2
CVSS 7.5
CVE-2025-53072 CRITICAL
Oracle Marketing 12.2.3-12.2.14 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
Details
Vulnerabilities 2,344
Exploit Likelihood High