CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,427 vulnerabilities with CWE-306
CVE-2025-55581
HIGH
D-Link DCS-825L <1.08.01 - Code Injection
CVSS 7.3
CVE-2025-9254
CRITICAL
WebITR < 2.1.0.33 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2025-47870
MEDIUM
Mattermost 9.11.0-9.11.17 10.5.0-10.5.8 10.8.0-10.8.3 10.9.0-10.9.2 - Team Invite ID Exposure via Restore Endpoint
CVSS 4.3
CVE-2025-27214
CRITICAL
UniFi Connect EV Station Pro <1.5.27 - Privilege Escalation
CVSS 9.8
CVE-2025-8611
CRITICAL
AOMEI Cyber Backup - Unauthenticated Remote Code Execution via DaoService
CVSS 9.8
CVE-2025-8610
CRITICAL
AOMEI Cyber Backup - Unauthenticated Remote Code Execution via StorageNode Service
CVSS 9.8
CVE-2025-51543
CRITICAL
Cicool builder <3.4.4 - Privilege Escalation
CVSS 9.8
CVE-2025-8450
HIGH
FileCatalyst 5.1.6-5.2.0 Build 80 - Unauthenticated Arbitrary File Upload via Workflow Order Forms
CVSS 8.2
CVE-2025-41689
HIGH
Wiesemann & Theis Motherbox 3 1.44-1.47 - Unauthenticated Sensitive Data Exposure
CVSS 7.5
CVE-2025-8995
CRITICAL
Authenticator Login < 2.1.4 - Authentication Bypass via Alternate Path
CVSS 9.8
CVE-2025-43983
CRITICAL
KuWFi CPF908-CP5 WEB5.0_LCD_20210125 - Info Disclosure
CVSS 9.1
CVE-2025-7774
HIGH
Digital Configurable - Privilege Escalation
CVE-2025-8943
CRITICAL
Flowise < 3.0.1 - Unauthenticated Remote Code Execution via Custom MCPs Feature
CVSS 9.8
CVE-2025-8754
HIGH
ABB AbilityTM zenon <14 - Info Disclosure
CVSS 7.5
CVE-2025-53789
HIGH
Windows StateRepository API - Privilege Escalation
CVSS 7.8
CVE-2025-54864
HIGH
NixOS Hydra < 2025-08-12 - Unauthenticated Denial of Service via GitHub/Gitea Push API
CVSS 7.5
CVE-2025-41686
HIGH
Phoenix Contact DaUM < 2025.3.1 - Privilege Escalation via Improper nssm.exe Permissions
CVSS 7.8
CVE-2025-7679
HIGH
ABB Aspect - Unauthenticated Authentication Bypass
CVSS 8.1
CVE-2025-54478
HIGH
Mattermost Confluence Plugin < 1.5.0 - Unauthenticated Channel Subscription Modification via API
CVSS 7.2
CVE-2025-44004
HIGH
Mattermost Confluence Plugin < 1.5.0 - Unauthenticated Channel Subscription via API Endpoint
CVSS 7.2
CVE-2025-5095
CRITICAL
Burk Technology ARC Solo - Auth Bypass
CVSS 9.8
CVE-2025-8284
CRITICAL
Packet Power EMX and EG - Unauthenticated Access to Monitoring and Control Functions
CVSS 9.8
CVE-2025-20702
HIGH
Airoha Bluetooth audio SDK - Privilege Escalation
CVSS 8.8
CVE-2025-20700
HIGH
Airoha Bluetooth audio SDK - Privilege Escalation
CVSS 8.8
CVE-2025-8286
CRITICAL
Güralp Systems FMUS Series - Unauthenticated Access
Details
Vulnerabilities
2,427
Exploit Likelihood
High