CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,426 vulnerabilities with CWE-306
CVE-2025-34220 MEDIUM
Vasion Print Virtual Appliance Host < 25.1.102 and Application < 25.1.1413 - Unauthenticated Group Enumeration
CVSS 5.3
CVE-2025-34218 CRITICAL
Vasion Print Virtual Appliance Host < 22.0.1049 and Application < 20.0.2786 - Unauthenticated Docker Instance Exposure
CVSS 9.8
CVE-2025-34216 CRITICAL
Vasion Print Virtual Appliance < 22.0.1026 & Application < 20.0.2702 - RCE via API APP_KEY Disclosure
CVSS 9.8
CVE-2025-34215 CRITICAL
Vasion Print Virtual Appliance < 22.0.1026 / Application < 20.0.2702 - RCE via Firmware Update
CVSS 9.8
CVE-2025-34207 CRITICAL
Vasion Print Virtual Appliance Host < 22.0.1049 and Application < 20.0.2786 - Insecure SSH Configuration
CVSS 9.8
CVE-2025-11130 HIGH
iHongRen pptp-vpn 1.0/1.0.1 - Missing Authentication
CVSS 8.4
CVE-2025-60251 MEDIUM
Unitree Go2-G1-H1-B2 - Info Disclosure
CVSS 5.0
CVE-2025-10906 HIGH
Magnetism Studios Endurance <3.3.0 - Use After Free
CVSS 8.4
CVE-2025-41716 MEDIUM
WAGO Solution Builder < 2.3.3 - Unauthenticated User Account Enumeration
CVSS 5.3
CVE-2025-41715 CRITICAL
WAGO Device Sphere < 1.1.0 and Solution Builder < 2.3.3 - Unauthenticated Database Access
CVSS 9.8
CVE-2025-57432 CRITICAL
Blackmagic Web Presenter 3.3 - Unauthenticated Remote Command Execution via Telnet Service
CVSS 9.8
CVE-2025-9983 HIGH
GALAYOU G2 - Unauthenticated RTSP Stream Access
CVE-2025-10772 MEDIUM
huggingface LeRobot <0.3.3 - Missing Authentication
CVSS 6.3
CVE-2025-34190 HIGH
Vasion Print Virtual Appliance Host < 25.1.102 & Application < 25.1.1413 - Authentication Bypass
CVSS 7.8
CVE-2025-10672 HIGH
whuan132 AIBattery <1.0.9 - Info Disclosure
CVSS 7.8
CVE-2025-59345 CRITICAL
Dragonfly < 2.1.0 - Unauthenticated Job Manipulation and Denial of Service via Manager API Endpoints
CVSS 9.1
CVE-2025-9971 CRITICAL
Planet Technology Industrial Cellular Gateway - Auth Bypass
CVSS 9.8
CVE-2025-56562 HIGH
Signify Wiz Connected 1.9.1 - Unauthenticated Denial of Service via MAC Address
CVSS 7.5
CVE-2025-59358 HIGH
Chaos Mesh < 2.7.3 - Unauthenticated Denial of Service via GraphQL Debugging Server
CVSS 7.5
CVE-2025-10452 CRITICAL
Statistical Database System - Auth Bypass
CVSS 9.8
CVE-2025-10204 HIGH
LG Electronics AC Smart II - Unauthenticated Administrator Password Change via Hidden Form
CVE-2025-58434 CRITICAL
Flowise <3.0.5 - Privilege Escalation
CVSS 9.8
CVE-2025-10267 MEDIUM
NUP Portal < SP5.0 - Unauthenticated Arbitrary File Upload and Remote Code Execution
CVSS 5.3
CVE-2025-9214 MEDIUM
Lenovo LJ2206W Printer < Ver.D(1.05) - Unauthenticated Info Disclosure & Network Settings Modification via CUPS
CVSS 5.4
CVE-2025-56405 HIGH
litmus mcp_server - Unauthenticated Improper Access Control via SSE Protocol
CVSS 7.5
Details
Vulnerabilities 2,426
Exploit Likelihood High