CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,428 vulnerabilities with CWE-306
CVE-2025-4268 MEDIUM
TOTOLINK A720R 4.1.5cu.374 - Auth Bypass
CVSS 5.3
CVE-2025-1495 MEDIUM
IBM Business Automation Workflow 24.0.0-24.0.1 IF001 - Unauthenticated Sensitive Information Exposure
CVSS 4.3
CVE-2025-24271 MEDIUM
iPadOS < 17.7.6 - Unauthenticated AirPlay Command Execution via Network Access
CVSS 5.4
CVE-2025-4019 HIGH
novel-plus < 5.1.1 - Missing Authentication in GeneratorController genCode Function
CVSS 7.3
CVE-2025-4018 MEDIUM
novel-plus < 5.1.1 - Missing Authentication in CrawlController addCrawlSource
CVSS 5.3
CVE-2025-4015 MEDIUM
novel-plus < 5.1.1 - Missing Authentication in SessionController
CVSS 5.3
CVE-2025-46275 CRITICAL
WGS-80HPT-V2 & WGS-4215-8T2S - Auth Bypass
CVSS 9.8
CVE-2025-34028 CRITICAL KEV
Commvault Command Center Innovation Release <11.38.20 - Path Traversal
CVSS 10.0
CVE-2025-32377 MEDIUM
Rasa Pro 3.9.0-3.9.19, 3.10.0-3.10.18, 3.11.0-3.11.6, 3.12.0-3.12.5 - Unauthenticated Voice Data Submission
CVSS 6.5
CVE-2025-32433 CRITICAL KEV
Erlang OTP Pre-Auth RCE Scanner and Exploit
CVSS 10.0
CVE-2025-27538 LOW
Mattermost <10.5.1-9.11.9 - Privilege Escalation
CVSS 2.2
CVE-2025-30215 CRITICAL
NATS-Server <2.10.27, 2.11.1 - Info Disclosure
CVSS 9.6
CVE-2025-32782 MEDIUM
Ash Authentication < 4.7.0 - Unauthenticated Account Confirmation via Email Link Auto-Follow
CVSS 5.3
CVE-2025-30727 CRITICAL
Oracle E-Business Suite 12.2.3-12.2.14 - Unauthenticated Remote Code Execution via iSurvey Module
CVSS 9.8
CVE-2025-2567 CRITICAL
Lantronix Xport 6.5.0.7 through 7.0.0.3 - Missing Authentication for Critical Function
CVSS 9.8
CVE-2025-0129 CRITICAL
Palo Alto Networks Prisma Access Browser - Privilege Escalation
CVE-2025-3474 MEDIUM
Drupal Panels < 4.9 - Unauthenticated Access Control Bypass via Incorrectly Configured Security Levels
CVSS 6.5
CVE-2025-29870 HIGH
Wi-Fi AP UNIT AC-WPS-11ac - Info Disclosure
CVSS 7.5
CVE-2025-3248 CRITICAL KEV
Langflow AI - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2025-32357 MEDIUM
Zammad 6.4.0-6.4.1 - Authenticated Unauthorized Knowledge Base Content Access via API
CVSS 4.3
CVE-2025-0257 MEDIUM
HCL DevOps Deploy/HCL Launch - Info Disclosure
CVSS 6.3
CVE-2025-25060 HIGH
AssetView and AssetView CLOUD < 13.2.4.3408 and < 13.3.4.3004 - Unauthenticated Arbitrary File Read and Delete
CVSS 8.2
CVE-2025-0256 MEDIUM
HCL DevOps Deploy/HCL Launch - Info Disclosure
CVSS 4.3
CVE-2025-25068 HIGH
Mattermost <10.4.2-10.5.0 - Auth Bypass
CVSS 7.5
CVE-2025-30111 HIGH
IROAD v9 - Unauthenticated Video Footage and Live Stream Access
CVSS 7.5
Details
Vulnerabilities 2,428
Exploit Likelihood High