CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,344 vulnerabilities with CWE-306
CVE-2025-10906
HIGH
Magnetism Studios Endurance <3.3.0 - Use After Free
CVSS 8.4
CVE-2025-41716
MEDIUM
WAGO Solution Builder < 2.3.3 - Unauthenticated User Account Enumeration
CVSS 5.3
CVE-2025-41715
CRITICAL
WAGO Device Sphere < 1.1.0 and Solution Builder < 2.3.3 - Unauthenticated Database Access
CVSS 9.8
CVE-2025-57432
CRITICAL
Blackmagic Web Presenter 3.3 - Unauthenticated Remote Command Execution via Telnet Service
CVSS 9.8
CVE-2025-9983
HIGH
GALAYOU G2 - Unauthenticated RTSP Stream Access
CVE-2025-10772
MEDIUM
huggingface LeRobot <0.3.3 - Missing Authentication
CVSS 6.3
CVE-2025-34190
HIGH
Vasion Print Virtual Appliance Host < 25.1.102 & Application < 25.1.1413 - Authentication Bypass
CVSS 7.8
CVE-2025-10672
HIGH
whuan132 AIBattery <1.0.9 - Info Disclosure
CVSS 7.8
CVE-2025-59345
CRITICAL
Dragonfly < 2.1.0 - Unauthenticated Job Manipulation and Denial of Service via Manager API Endpoints
CVSS 9.1
CVE-2025-9971
CRITICAL
Planet Technology Industrial Cellular Gateway - Auth Bypass
CVSS 9.8
CVE-2025-56562
HIGH
Signify Wiz Connected 1.9.1 - Unauthenticated Denial of Service via MAC Address
CVSS 7.5
CVE-2025-59358
HIGH
Chaos Mesh < 2.7.3 - Unauthenticated Denial of Service via GraphQL Debugging Server
CVSS 7.5
CVE-2025-10452
CRITICAL
Statistical Database System - Auth Bypass
CVSS 9.8
CVE-2025-10204
HIGH
LG Electronics AC Smart II - Unauthenticated Administrator Password Change via Hidden Form
CVE-2025-58434
CRITICAL
Flowise <3.0.5 - Privilege Escalation
CVSS 9.8
CVE-2025-10267
MEDIUM
NUP Portal < SP5.0 - Unauthenticated Arbitrary File Upload and Remote Code Execution
CVSS 5.3
CVE-2025-9214
MEDIUM
Lenovo LJ2206W Printer < Ver.D(1.05) - Unauthenticated Info Disclosure & Network Settings Modification via CUPS
CVSS 5.4
CVE-2025-56405
HIGH
litmus mcp_server - Unauthenticated Improper Access Control via SSE Protocol
CVSS 7.5
CVE-2025-36757
MEDIUM
SolaX Cloud - Unauthenticated Administrator Login Bypass via Parameter Tampering
CVE-2025-36756
MEDIUM
SolaX Cloud - Unauthenticated Account Takeover via Serial Number
CVE-2025-7635
HIGH
Calix GigaCenter ONT 844E, 844G, 844GE, 854GE - Unauthenticated Telnet Root Access
CVSS 7.7
CVE-2025-9994
CRITICAL
Amp'ed RF BT-AP 111 - Info Disclosure
CVSS 9.8
CVE-2025-9160
HIGH
Rockwell Automation CompactLogix 5480 - Maintenance Menu Code Execution
CVE-2025-7970
HIGH
FactoryTalk Activation Manager 5.00.00-5.01.01 - Missing Authentication for Critical Function
CVSS 7.5
CVE-2025-42926
MEDIUM
SAP NetWeaver Application Server Java - Unauthenticated Sensitive Information Exposure via Internal File Access
CVSS 5.3
Details
Vulnerabilities
2,344
Exploit Likelihood
High