CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,427 vulnerabilities with CWE-306
CVE-2025-3699 CRITICAL
Mitsubishi Electric Corporation - Missing Authentication
CVSS 9.8
CVE-2025-1754 MEDIUM
GitLab CE/EE <17.11.5, <18.0.3, <18.1.1 - Unauthenticated File Upload
CVSS 5.3
CVE-2025-6678 HIGH
Autel MaxiCharger AC Wallbox Commercial - Unauthenticated Information Disclosure via Pile API
CVSS 7.5
CVE-2025-32978 HIGH
Quest KACE SMA <14.1.101 - Unauth DoS
CVSS 7.5
CVE-2025-3090 HIGH
Unknown Device - Info Disclosure/DoS
CVSS 8.2
CVE-2025-48469 CRITICAL
Advantech WISE-4000 LAN Firmware Update - Unauthenticated Firmware Upload
CVSS 9.6
CVE-2025-34039 CRITICAL
Yonyou UFIDA NC <6.5 - Code Injection
CVE-2025-3319 HIGH
IBM Spectrum Protect Server <8.1.27 - Auth Bypass
CVSS 8.1
CVE-2025-32879 HIGH
COROS PACE 3 Firmware < 3.0808.0 - Unauthenticated BLE Connection and Device Control
CVSS 8.8
CVE-2025-32876 MEDIUM
COROS PACE 3 Firmware < 3.0808.0 - Unauthenticated BLE Legacy Pairing Key Guessing
CVSS 6.8
CVE-2025-32896 MEDIUM
Apache SeaTunnel <= 2.3.10 - Unauthenticated Arbitrary File Read and Deserialization via Hazelcast REST API
CVSS 6.5
CVE-2025-25265 MEDIUM
WAGO CC100, PFC100, PFC200, TP600 - Unauthenticated Arbitrary File Read via Configuration Web Application
CVSS 4.9
CVE-2025-49596 CRITICAL
MCP Inspector < 0.14.1 - Unauthenticated Remote Code Execution via Stdio Command Injection
CVE-2025-5906 HIGH
code-projects Laundry System 1.0 - Missing Authentication in /data/ Endpoint
CVSS 7.3
CVE-2025-26468 HIGH
CyberData 011209 SIP Emergency Intercom < 22.0.1 - Unauthenticated Denial of Service
CVSS 7.5
CVE-2025-49652 CRITICAL
BackendAI < 25.15.6 - Unauthenticated User Registration Bypass
CVSS 9.8
CVE-2025-5876 MEDIUM
Lucky LM-520-SC,LM-520-FSC,Lucky LM-520-FSC-SAM <20250321 - Missing...
CVSS 5.3
CVE-2025-5872 MEDIUM
eGauge EG3000 Energy Monitor <3.6.3 - Missing Authentication
CVSS 5.3
CVE-2025-5871 MEDIUM
Papendorf SOL Connect Center 3.3.0.0 - Auth Bypass
CVSS 5.3
CVE-2025-3461 CRITICAL
onsemi Quantenna Wi-Fi Firmware - Unauthenticated Remote Access via Telnet Interface
CVSS 9.1
CVE-2025-5192 HIGH
Scshr HR Portal < 7.3.2025.0408 - Missing Authentication
CVSS 7.5
CVE-2025-5719 MEDIUM
vivo Wallet < 5.1.8.0 - Unauthenticated Authentication Bypass
CVE-2025-5715 LOW
Signal 7.41.4 - Missing Critical Step in Biometric Authentication
CVSS 3.8
CVE-2025-1701 HIGH
MIM Admin Service RMI - Local Code Execution
CVE-2025-47272 MEDIUM
CE Phoenix eCommerce <1.1.0.3 - Auth Bypass
CVSS 5.5
Details
Vulnerabilities 2,427
Exploit Likelihood High