CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,427 vulnerabilities with CWE-306
CVE-2025-55581 HIGH
D-Link DCS-825L <1.08.01 - Code Injection
CVSS 7.3
CVE-2025-9254 CRITICAL
WebITR < 2.1.0.33 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2025-47870 MEDIUM
Mattermost 9.11.0-9.11.17 10.5.0-10.5.8 10.8.0-10.8.3 10.9.0-10.9.2 - Team Invite ID Exposure via Restore Endpoint
CVSS 4.3
CVE-2025-27214 CRITICAL
UniFi Connect EV Station Pro <1.5.27 - Privilege Escalation
CVSS 9.8
CVE-2025-8611 CRITICAL
AOMEI Cyber Backup - Unauthenticated Remote Code Execution via DaoService
CVSS 9.8
CVE-2025-8610 CRITICAL
AOMEI Cyber Backup - Unauthenticated Remote Code Execution via StorageNode Service
CVSS 9.8
CVE-2025-51543 CRITICAL
Cicool builder <3.4.4 - Privilege Escalation
CVSS 9.8
CVE-2025-8450 HIGH
FileCatalyst 5.1.6-5.2.0 Build 80 - Unauthenticated Arbitrary File Upload via Workflow Order Forms
CVSS 8.2
CVE-2025-41689 HIGH
Wiesemann & Theis Motherbox 3 1.44-1.47 - Unauthenticated Sensitive Data Exposure
CVSS 7.5
CVE-2025-8995 CRITICAL
Authenticator Login < 2.1.4 - Authentication Bypass via Alternate Path
CVSS 9.8
CVE-2025-43983 CRITICAL
KuWFi CPF908-CP5 WEB5.0_LCD_20210125 - Info Disclosure
CVSS 9.1
CVE-2025-7774 HIGH
Digital Configurable - Privilege Escalation
CVE-2025-8943 CRITICAL
Flowise < 3.0.1 - Unauthenticated Remote Code Execution via Custom MCPs Feature
CVSS 9.8
CVE-2025-8754 HIGH
ABB AbilityTM zenon <14 - Info Disclosure
CVSS 7.5
CVE-2025-53789 HIGH
Windows StateRepository API - Privilege Escalation
CVSS 7.8
CVE-2025-54864 HIGH
NixOS Hydra < 2025-08-12 - Unauthenticated Denial of Service via GitHub/Gitea Push API
CVSS 7.5
CVE-2025-41686 HIGH
Phoenix Contact DaUM < 2025.3.1 - Privilege Escalation via Improper nssm.exe Permissions
CVSS 7.8
CVE-2025-7679 HIGH
ABB Aspect - Unauthenticated Authentication Bypass
CVSS 8.1
CVE-2025-54478 HIGH
Mattermost Confluence Plugin < 1.5.0 - Unauthenticated Channel Subscription Modification via API
CVSS 7.2
CVE-2025-44004 HIGH
Mattermost Confluence Plugin < 1.5.0 - Unauthenticated Channel Subscription via API Endpoint
CVSS 7.2
CVE-2025-5095 CRITICAL
Burk Technology ARC Solo - Auth Bypass
CVSS 9.8
CVE-2025-8284 CRITICAL
Packet Power EMX and EG - Unauthenticated Access to Monitoring and Control Functions
CVSS 9.8
CVE-2025-20702 HIGH
Airoha Bluetooth audio SDK - Privilege Escalation
CVSS 8.8
CVE-2025-20700 HIGH
Airoha Bluetooth audio SDK - Privilege Escalation
CVSS 8.8
CVE-2025-8286 CRITICAL
Güralp Systems FMUS Series - Unauthenticated Access
Details
Vulnerabilities 2,427
Exploit Likelihood High