CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,428 vulnerabilities with CWE-306
CVE-2024-57055
MEDIUM
WombatDialer < 25.02 - Unauthenticated Server-Side Access Control Bypass
CVSS 5.0
CVE-2024-57725
MEDIUM
Arcadyan Livebox Fibra PRV3399B_B_LT - Info Disclosure
CVSS 6.5
CVE-2024-10649
MEDIUM
wandb/openui < latest - Unauthenticated Arbitrary File Upload and Download via S3 Endpoints
CVSS 6.1
CVE-2024-54176
MEDIUM
IBM DevOps Deploy <8.0.1.4, UCD <7.3.2 - Info Disclosure
CVSS 4.3
CVE-2024-36555
CRITICAL
Forever KidsWatch - Privilege Escalation
CVSS 9.8
CVE-2024-9644
CRITICAL
Four-Faith F3x36 Firmware v2.0.0 - Authentication Bypass via bapply.cgi Endpoint
CVSS 9.8
CVE-2024-12511
HIGH
Xerox VersaLink - Unauthenticated SMB/FTP Settings Modification via Address Book Access
CVSS 7.6
CVE-2024-12957
HIGH
ASUS Armoury Crate 2.3.4.0-5.9.9.0 - Unauthenticated Arbitrary File Deletion
CVE-2024-12857
CRITICAL
AdForest < 5.1.8 - Unauthenticated Authentication Bypass via OTP Login
CVSS 9.8
CVE-2024-12757
HIGH
Nedap Librix Ecoreader - Unauthenticated Remote Code Execution
CVSS 8.6
CVE-2024-39773
MEDIUM
Wavlink AC3000 M33A8.V5030.210505 - Unauthenticated Information Disclosure via testsave.sh
CVSS 5.3
CVE-2024-39608
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Unauthenticated Arbitrary Firmware Update via login.cgi
CVSS 10.0
CVE-2024-39273
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Unauthenticated Arbitrary Firmware Update via fw_check.sh
CVSS 9.0
CVE-2024-35277
HIGH
FortiManager 6.4.0-6.4.14, 7.0.0-7.0.12, 7.2.0-7.2.5, 7.4.0-7.4.2 - Unauthenticated Access to Config
CVSS 8.6
CVE-2024-12847
CRITICAL
NETGEAR DGN1000 < 1.1.00.48 - Unauthenticated OS Command Injection via setup.cgi
CVSS 9.8
CVE-2024-13186
HIGH
vivo MinigameCenter < 2.2.4.0 - Information Disclosure via URL Loading
CVSS 7.5
CVE-2024-13185
HIGH
vivo MinigameCenter < 2.3.5.0 - Information Disclosure via URL Loading
CVSS 7.5
CVE-2024-13173
HIGH
Health Module <unknown - Info Disclosure
CVSS 7.5
CVE-2024-55538
MEDIUM
Acronis True Image <41725-41736 - Info Disclosure
CVSS 4.0
CVE-2024-12106
CRITICAL
WhatsUp Gold 23.1.0-24.0.1 - Unauthenticated LDAP Settings Modification
CVSS 9.4
CVE-2024-56799
CRITICAL
TrueWinter simofa < 0.2.7 - Unauthenticated Access to Restricted API Routes
CVSS 10.0
CVE-2024-7726
MEDIUM
Kioxia CM6, PM6 and PM7 Firmware - Unauthenticated Physical Access via JTAG Debug Port
CVSS 6.8
CVE-2024-54984
CRITICAL
Quectel BG96 BG96MAR02A08M1G - Auth Bypass
CVSS 9.8
CVE-2024-54983
CRITICAL
Quectel BC95-CNV <V100R001C00SPC051 - Auth Bypass
CVSS 9.8
CVE-2024-12371
CRITICAL
Rockwell Automation Power Monitor 1000 - Privilege Escalation
Details
Vulnerabilities
2,428
Exploit Likelihood
High