CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,427 vulnerabilities with CWE-306
CVE-2025-1907 CRITICAL
Instantel Micromate - Command Injection
CVSS 9.8
CVE-2025-22252 CRITICAL
FortiProxy 7.6.0-7.6.1, FortiSwitchManager 7.2.5, FortiOS 7.4.4-7.4.6, 7.6.0 - Authentication Bypass
CVSS 9.8
CVE-2025-32440 CRITICAL
netalertx < 25.4.14 - Unauthenticated Settings Update via Crafted Request to index.php
CVSS 10.0
CVE-2025-41651 CRITICAL
Weidmueller Industrial Ethernet Switches - Unauthenticated Command Execution
CVSS 9.8
CVE-2025-2407 CRITICAL
Mobatime AMX MTAPI <1.5 - Auth Bypass
CVE-2025-48742 MEDIUM
SIGB PMB < 8.0.1.2 - Remote Code Execution via Installer
CVSS 5.4
CVE-2025-40664 CRITICAL
TCMAN GIM v11 - Unauthenticated Critical Function Access via User Management Endpoints
CVSS 9.1
CVE-2025-41655 HIGH
Pepperl+Fuchs Profinet Gateway FB8122A.1.EL and LB8122A.1.EL < V1.3.13 - DoS via Reboot URL
CVSS 7.5
CVE-2025-41654 HIGH
Pepperl+Fuchs Profinet Gateway FB8122A.1.EL/LB8122A.1.EL < V1.3.13 - SNMP Info Disclosure & DoS
CVSS 8.2
CVE-2025-36535 CRITICAL
AutomationDirect MB-Gateway Web Server - Unauthenticated Configuration Access
CVSS 10.0
CVE-2025-4008 HIGH KEV
Meteobridge VM and Firmware < 6.2 - Unauthenticated Remote Command Execution
CVSS 8.8
CVE-2025-27803 MEDIUM
eCharge Hardy Barth cPH2 / cPP2 charging stations <= 2.2.0 - Unauthenticated Administrative Access
CVSS 6.5
CVE-2025-48391 HIGH
JetBrains YouTrack <2025.1.76253 - Info Disclosure
CVSS 7.7
CVE-2025-47850 MEDIUM
JetBrains YouTrack < 2025.1.74704 - Unauthenticated Restricted Attachment Exposure via Issue Cloning
CVSS 4.3
CVE-2025-32738 MEDIUM
I-O DATA HDL-T Series <= 1.21 - Unauthenticated Critical Function Access
CVSS 5.3
CVE-2025-0132 MEDIUM
Palo Alto Networks Cortex XDR - DoS
CVE-2025-44039 MEDIUM
CP-XR-DE21-S Firmware 1.031.022 - Unauthenticated Sensitive Information Exposure via UART Console
CVSS 5.1
CVE-2025-4560 MEDIUM
ISOinsight from Netvision - Info Disclosure
CVSS 6.5
CVE-2025-4557 CRITICAL
Parking Management System - Auth Bypass
CVSS 9.1
CVE-2025-4555 CRITICAL
Okcat Parking Management Platform - Auth Bypass
CVSS 9.8
CVE-2025-4382 MEDIUM
LUKS-encrypted disks - Info Disclosure
CVSS 5.9
CVE-2025-3759 HIGH
Netis Systems WF2220 >=1.2.31706 <1.2.31706 - Unauthenticated Administrator Account Hijacking via netcore_set.cgi
CVE-2025-3758 HIGH
Netis Systems WF2220 - Unauthenticated Plaintext Password Exposure via netcore_get.cgi Endpoint
CVE-2025-20210 HIGH
Cisco Catalyst Center - Info Disclosure
CVSS 7.3
CVE-2025-4268 MEDIUM
TOTOLINK A720R 4.1.5cu.374 - Auth Bypass
CVSS 5.3
Details
Vulnerabilities 2,427
Exploit Likelihood High