CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,344 vulnerabilities with CWE-306
CVE-2025-12447
MEDIUM
Google Chrome < 142.0.7444.59 - UI Spoofing via Omnibox Security UI
CVSS 4.2
CVE-2025-12444
MEDIUM
Google Chrome < 142.0.7444.59 - UI Spoofing via Fullscreen Security UI
CVSS 4.2
CVE-2025-12436
MEDIUM
Google Chrome < 142.0.7444.59 - Policy Bypass in Extensions
CVSS 5.9
CVE-2025-20358
CRITICAL
Cisco Unified Contact Center Express - Unauthenticated Remote Code Execution via Authentication Bypass
CVSS 9.4
CVE-2025-55108
CRITICAL
BMC Control-M/Agent 9.0.18-9.0.22 - Unauthenticated Remote Code Execution and Arbitrary File Read/Write
CVSS 10.0
CVE-2025-12108
CRITICAL
Survision LPR Camera - Info Disclosure
CVE-2025-61956
CRITICAL
Radiometrics VizAir < 2025-08 - Unauthenticated Critical Function Access
CVSS 10.0
CVE-2025-61945
CRITICAL
Radiometrics VizAir < 2025-08 - Unauthenticated Admin Panel Access
CVSS 10.0
CVE-2025-47357
HIGH
Qualcomm Firmware - Unauthenticated Information Disclosure via QFPROM Fuse Region Access
CVSS 8.0
CVE-2025-11007
CRITICAL
CE21 Suite 2.2.1-2.3.1 - Unauthenticated Plugin Settings Update via wp_ajax_nopriv_ce21_single_sign_on_save_api_settings
CVSS 9.8
CVE-2025-8558
MEDIUM
Proofpoint Insider Threat Management Server < 7.17.2 - Unauthenticated Agent Unregistration via Adjacent Network
CVSS 5.4
CVE-2025-48397
HIGH
Eaton BLSS <7.3.0.SCP004 - Auth Bypass
CVSS 7.1
CVE-2025-52665
CRITICAL
UniFi Access 3.3.22-3.4.31 - Unauthenticated Management API Exposure
CVSS 10.0
CVE-2025-12477
CRITICAL
BLU-IC2 and BLU-IC4 < 1.20 - Server Version Disclosure
CVSS 9.8
CVE-2025-12476
CRITICAL
BLU-IC2 and BLU-IC4 Firmware < 1.20 - Unauthenticated Access to Critical Function
CVSS 9.8
CVE-2025-41090
HIGH
microCLAUDIA <3.2.0 - Privilege Escalation
CVE-2025-43994
HIGH
Dell Storage Manager 20.1.21 - Unauthenticated Information Disclosure
CVSS 8.6
CVE-2025-62607
MEDIUM
nautobot-ssot < 3.10.0 - Unauthenticated Information Disclosure via Configuration Page
CVSS 5.3
CVE-2025-41110
HIGH
Ghost Robotics Vision 60 v0.27.2 - Improper Authentication via Hardcoded WiFi and SSH Credentials
CVSS 8.8
CVE-2025-61756
HIGH
Oracle Financial Services Analytical ... - Missing Authentication
CVSS 7.5
CVE-2025-62481
CRITICAL
Oracle Marketing 12.2.3-12.2.14 - Unauthenticated Authentication Bypass in Marketing Administration
CVSS 9.8
CVE-2025-62287
MEDIUM
Oracle Life Sciences InForm 7.0.1.0 - Unauthenticated Data Manipulation and Read Access via Web Server
CVSS 6.1
CVE-2025-61757
CRITICAL
KEV
Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 - Unauthenticated Remote Code Execution via REST WebServices
CVSS 9.8
CVE-2025-61752
HIGH
Oracle WebLogic Server 14.1.1.0.0 and 14.1.2.0.0 - Unauthenticated Denial of Service via HTTP/2
CVSS 7.5
CVE-2025-53072
CRITICAL
Oracle Marketing 12.2.3-12.2.14 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
Details
Vulnerabilities
2,344
Exploit Likelihood
High