CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,344 vulnerabilities with CWE-306
CVE-2025-53037 CRITICAL
Oracle Financial Services Analytical Applications Infrastructure 8.0.7.9/8.0.8.7/8.1.2.5 - RCE via HTTP
CVSS 9.8
CVE-2025-53034 MEDIUM
Oracle Financial Services Analytical ... - Missing Authentication
CVSS 5.4
CVE-2025-11949 HIGH
EasyFlow .NET & EasyFlow AiNet - Auth Bypass
CVSS 7.5
CVE-2025-9574 CRITICAL
ABB ALS-mini-s4/8 - Info Disclosure
CVSS 10.0
CVE-2025-60856 MEDIUM
Reolink Video Doorbell WiFi DB_566128M5MP_W - RCE
CVSS 6.8
CVE-2025-11942 HIGH
70mai X200 Firmware < 2025-10-10 - Improper Authentication in Pairing
CVSS 7.3
CVE-2025-11852 MEDIUM
Apeman ID71 218.53.203.117 - Unauthenticated Improper Authentication in ONVIF Service
CVSS 5.3
CVE-2025-62586 CRITICAL
OPEXUS FOIAXpress 11.1.0-11.13.1.9 - Unauthenticated Administrator Password Reset
CVSS 9.8
CVE-2025-9152 CRITICAL
WSO2 API Manager - Privilege Escalation
CVSS 9.8
CVE-2025-0275 MEDIUM
HCL BigFix Mobile <3.3 - Privilege Escalation
CVSS 5.3
CVE-2025-0274 MEDIUM
HCL BigFix MCM <3.3 - Privilege Escalation
CVSS 5.3
CVE-2025-11728 MEDIUM
Oceanpayment CreditCard Gateway <6.0 - Info Disclosure
CVSS 5.3
CVE-2025-23356 HIGH
NVIDIA Isaac Lab < 2.2.1 - Remote Code Execution via SB3 Configuration Parsing
CVSS 8.4
CVE-2025-7328 CRITICAL
Rockwell Automation 1783-NATR Firmware < 1.007 - Unauthenticated Denial of Service and Admin Account Takeover
CVSS 9.8
CVE-2025-40771 CRITICAL
SIMATIC CP 1542SP-1, CP 1543SP-1 < V2.4.24 - Unauthenticated Configuration Data Access
CVSS 9.8
CVE-2025-40765 CRITICAL
TeleControl Server Basic V3.1 >= 3.1.2.2 < 3.1.2.3 - Unauthenticated Information Disclosure
CVSS 9.8
CVE-2025-41703 HIGH
Phoenix Contact QUINT4-UPS - Unauthenticated Denial of Service via Modbus Command
CVSS 7.5
CVE-2025-11672 MEDIUM
Uniweb/SoliPACS WebServer - Info Disclosure
CVSS 5.3
CVE-2025-11671 MEDIUM
Uniweb/SoliPACS WebServer - Info Disclosure
CVSS 5.3
CVE-2025-11661 HIGH
oranbyte School Management System - Improper Authentication
CVSS 7.3
CVE-2025-61928 CRITICAL
better-auth < 1.3.26 - Unauthenticated API Key Creation and Modification via User ID Injection
CVE-2025-59246 CRITICAL
Azure Entra ID - Elevation of Privilege via Missing Authentication
CVSS 9.8
CVE-2025-35051 CRITICAL
Newforma Project Center Server - Unauthenticated Remote Code Execution via .NET Deserialization
CVSS 9.8
CVE-2025-35050 CRITICAL
Newforma Project Center - RCE via .NET Deserialization in /remoteweb/remote.rem
CVSS 9.8
CVE-2025-11198 HIGH
Juniper Security Director Policy Enforcer < 23.1R1 Hotpatch v3 - Unauthenticated Image Replacement via vSRX Deployment
CVSS 7.4
Details
Vulnerabilities 2,344
Exploit Likelihood High