CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,428 vulnerabilities with CWE-306
CVE-2024-47865
MEDIUM
Rakuten Turbo 5G <= V1.3.18 - Unauthenticated Firmware Update
CVSS 5.3
CVE-2024-0012
CRITICAL
KEV
Palo Alto Networks PAN-OS 10.2 11.0 11.1 11.2 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2024-41969
HIGH
WAGO CC100, PFC100 G2, PFC200 G2, TP600, Edge Controller < 4.5.10 (FW27) - Missing Authentication
CVSS 8.8
CVE-2024-41968
MEDIUM
WAGO CC100, PFC100 G2, PFC200 G2, TP600, Edge Controller < 4.5.10 (FW27) - DoS via Docker Settings
CVSS 5.4
CVE-2024-41967
HIGH
Device <unknown> - Privilege Escalation
CVSS 8.1
CVE-2024-10924
CRITICAL
WordPress Really Simple SSL Plugin Authentication Bypass to RCE
CVSS 9.8
CVE-2024-48966
CRITICAL
Baxter Life2000 Ventilation System < 06.08.00.00 - Unauthenticated Info Disclosure & Settings Manipulation
CVSS 10.0
CVE-2024-39707
MEDIUM
Insyde IHISI - Privilege Escalation
CVSS 5.3
CVE-2024-40408
HIGH
Cybele Software Thinfinity Workspace <7.0.2.113 - Privilege Escalation
CVSS 7.3
CVE-2024-40405
HIGH
Cybele Software Thinfinity Workspace <7.0.3.109 - Privilege Escalation
CVSS 8.1
CVE-2024-40404
CRITICAL
Cybele Software Thinfinity Workspace <7.0.2.113 - Privilege Escala...
CVSS 9.8
CVE-2024-47574
HIGH
Fortinet FortiClientWindows <7.4.0 - Privilege Escalation
CVSS 7.8
CVE-2024-7516
HIGH
Brocade Fabric OS < 9.2.2 - Unauthenticated Service Session Hijacking via SSH Key Forgery
CVSS 7.1
CVE-2024-26011
MEDIUM
Fortinet Fortios < 7.0.15 - Missing Authentication
CVSS 5.3
CVE-2024-8074
CRITICAL
Nomysoft Informatics Nomysem <13.10.2024 - Info Disclosure
CVE-2024-10284
CRITICAL
CE21 Suite plugin <2.2.0 - Auth Bypass
CVSS 9.8
CVE-2024-50589
HIGH
HASOMED Elefant < 24.04.00 - Unauthenticated Sensitive Data Exposure via FHIR API
CVSS 7.5
CVE-2024-48953
HIGH
Logpoint SIEM < 7.5.0 - Unauthenticated Authentication Bypass via Third-Party Module Endpoints
CVSS 7.5
CVE-2024-48952
MEDIUM
Logpoint SOAR < 7.5.0 - Unauthenticated API Access via Static JWT Key
CVSS 6.4
CVE-2024-48950
HIGH
Logpoint SIEM < 7.5.0 - Unauthenticated Authentication Bypass via Distributed Setup Endpoint
CVSS 7.5
CVE-2024-51493
MEDIUM
OctoPrint <= 1.10.2 - Unverified Password Change via Stolen API Key
CVSS 5.3
CVE-2024-51362
MEDIUM
LSC Smart Connect Indoor IP Camera V7.6.32 - Info Disclosure
CVSS 6.5
CVE-2024-9430
MEDIUM
Get Quote For Woocommerce <1.0.0 - Info Disclosure
CVSS 5.3
CVE-2024-51567
CRITICAL
KEV
CyberPanel Multi CVE Pre-auth RCE
CVSS 10.0
CVE-2024-50488
HIGH
Token Login <= 1.0.3 - Authentication Bypass
CVSS 8.8
Details
Vulnerabilities
2,428
Exploit Likelihood
High