CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,428 vulnerabilities with CWE-306
CVE-2024-57055 MEDIUM
WombatDialer < 25.02 - Unauthenticated Server-Side Access Control Bypass
CVSS 5.0
CVE-2024-57725 MEDIUM
Arcadyan Livebox Fibra PRV3399B_B_LT - Info Disclosure
CVSS 6.5
CVE-2024-10649 MEDIUM
wandb/openui < latest - Unauthenticated Arbitrary File Upload and Download via S3 Endpoints
CVSS 6.1
CVE-2024-54176 MEDIUM
IBM DevOps Deploy <8.0.1.4, UCD <7.3.2 - Info Disclosure
CVSS 4.3
CVE-2024-36555 CRITICAL
Forever KidsWatch - Privilege Escalation
CVSS 9.8
CVE-2024-9644 CRITICAL
Four-Faith F3x36 Firmware v2.0.0 - Authentication Bypass via bapply.cgi Endpoint
CVSS 9.8
CVE-2024-12511 HIGH
Xerox VersaLink - Unauthenticated SMB/FTP Settings Modification via Address Book Access
CVSS 7.6
CVE-2024-12957 HIGH
ASUS Armoury Crate 2.3.4.0-5.9.9.0 - Unauthenticated Arbitrary File Deletion
CVE-2024-12857 CRITICAL
AdForest < 5.1.8 - Unauthenticated Authentication Bypass via OTP Login
CVSS 9.8
CVE-2024-12757 HIGH
Nedap Librix Ecoreader - Unauthenticated Remote Code Execution
CVSS 8.6
CVE-2024-39773 MEDIUM
Wavlink AC3000 M33A8.V5030.210505 - Unauthenticated Information Disclosure via testsave.sh
CVSS 5.3
CVE-2024-39608 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Unauthenticated Arbitrary Firmware Update via login.cgi
CVSS 10.0
CVE-2024-39273 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Unauthenticated Arbitrary Firmware Update via fw_check.sh
CVSS 9.0
CVE-2024-35277 HIGH
FortiManager 6.4.0-6.4.14, 7.0.0-7.0.12, 7.2.0-7.2.5, 7.4.0-7.4.2 - Unauthenticated Access to Config
CVSS 8.6
CVE-2024-12847 CRITICAL
NETGEAR DGN1000 < 1.1.00.48 - Unauthenticated OS Command Injection via setup.cgi
CVSS 9.8
CVE-2024-13186 HIGH
vivo MinigameCenter < 2.2.4.0 - Information Disclosure via URL Loading
CVSS 7.5
CVE-2024-13185 HIGH
vivo MinigameCenter < 2.3.5.0 - Information Disclosure via URL Loading
CVSS 7.5
CVE-2024-13173 HIGH
Health Module <unknown - Info Disclosure
CVSS 7.5
CVE-2024-55538 MEDIUM
Acronis True Image <41725-41736 - Info Disclosure
CVSS 4.0
CVE-2024-12106 CRITICAL
WhatsUp Gold 23.1.0-24.0.1 - Unauthenticated LDAP Settings Modification
CVSS 9.4
CVE-2024-56799 CRITICAL
TrueWinter simofa < 0.2.7 - Unauthenticated Access to Restricted API Routes
CVSS 10.0
CVE-2024-7726 MEDIUM
Kioxia CM6, PM6 and PM7 Firmware - Unauthenticated Physical Access via JTAG Debug Port
CVSS 6.8
CVE-2024-54984 CRITICAL
Quectel BG96 BG96MAR02A08M1G - Auth Bypass
CVSS 9.8
CVE-2024-54983 CRITICAL
Quectel BC95-CNV <V100R001C00SPC051 - Auth Bypass
CVSS 9.8
CVE-2024-12371 CRITICAL
Rockwell Automation Power Monitor 1000 - Privilege Escalation
Details
Vulnerabilities 2,428
Exploit Likelihood High