CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,428 vulnerabilities with CWE-306
CVE-2024-9062 HIGH
Archify < 1.3.1 - Local Privilege Escalation via XPC Helper Tool
CVSS 7.8
CVE-2024-55585 CRITICAL
moPS App <1.8.618 - Info Disclosure
CVE-2024-46506 CRITICAL
Unauthenticated RCE in NetAlertX
CVSS 10.0
CVE-2024-23815 HIGH
Siemens Desigo CC - Unauthenticated SQL Query Execution via Event Port
CVSS 7.5
CVE-2024-42178 LOW
HCL MyXalytics - Unauthenticated Information Disclosure via Unrestricted URL Access
CVSS 2.5
CVE-2024-41793 HIGH
SENTRON 7KT PAC1260 Data Manager - Unauthenticated SSH Service Enablement via Web Interface
CVSS 8.6
CVE-2024-41791 HIGH
SENTRON 7KT PAC1260 Data Manager - Unauthenticated Critical Function Access via Web Interface
CVSS 7.3
CVE-2024-13553 CRITICAL
SMS Alert Order Notifications < 3.7.9 - Unauthenticated Privilege Escalation via Host Header Spoofing
CVSS 9.8
CVE-2024-56469 MEDIUM
IBM UrbanCode Deploy/DevOps Deploy <7.3.2.10, <8.1.0.1 - Privilege ...
CVSS 6.3
CVE-2024-45356 HIGH
Xiaomi Phone Framework - Privilege Escalation
CVSS 7.3
CVE-2024-45355 MEDIUM
Xiaomi Phone Framework - Privilege Escalation
CVSS 5.5
CVE-2024-45483 HIGH
B&R APROL <4.4-01 - Info Disclosure
CVE-2024-9919 HIGH
lollms_web_ui - Unauthenticated Directory Deletion via Uninstall Endpoint
CVSS 8.4
CVE-2024-8196 CRITICAL
AnythingLLM Desktop < 1.6.5 - Unauthenticated Backend Access via Open Port
CVSS 9.8
CVE-2024-8057 MEDIUM
danswer-ai/danswer < latest - Unauthenticated Privilege Escalation via Connector Credential Linking
CVSS 4.3
CVE-2024-8053 HIGH
open-webui/open-webui <0.3.10 - DoS
CVSS 8.2
CVE-2024-6842 HIGH
mintplex-labs/anything-llm <1.5.5 - Info Disclosure
CVSS 7.5
CVE-2024-12869 MEDIUM
ragflow v0.12.0 - Unauthenticated User Invite List Exposure
CVSS 4.3
CVE-2024-50630 HIGH
Synology Drive Server < 3.0.4-12699 - Unauthenticated Administrator Credential Exposure via WebAPI
CVSS 7.5
CVE-2024-23943 CRITICAL
MB connect line mbCONNECT24 < 2.16.2 and mbNET < 8.2.0 - Unauthenticated Cloud API Access
CVSS 9.1
CVE-2024-13772 MEDIUM
Civi WordPress Theme <= 2.1.6.1 - Unauthenticated Authentication Bypass via Social Login
CVSS 5.6
CVE-2024-13771 CRITICAL
Civi WordPress Theme <= 2.1.4 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2024-52285 MEDIUM
SiPass integrated AC5102/ACC-AP <6.4.8 - Info Disclosure
CVSS 5.3
CVE-2024-9658 HIGH
School Management System for Wordpress < 93.0.0 - Authenticated Privilege Escalation via User Detail Update Functions
CVSS 8.8
CVE-2024-31525 HIGH
Peppermint Ticket Management 0.4.6 - Privilege Escalation
CVSS 7.2
Details
Vulnerabilities 2,428
Exploit Likelihood High