CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,428 vulnerabilities with CWE-306
CVE-2024-50489
CRITICAL
Realty Workstation <= 1.0.45 - Authentication Bypass
CVSS 9.8
CVE-2024-50487
CRITICAL
MaanStore API <= 1.0.1 - Authentication Bypass
CVSS 9.8
CVE-2024-50486
CRITICAL
Acnoo Flutter API <= 1.0.5 - Authentication Bypass
CVSS 9.8
CVE-2024-50477
CRITICAL
Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass
CVSS 9.8
CVE-2024-10386
CRITICAL
Rockwell Automation ThinManager 11.2.0-11.2.9 - Unauthenticated Database Manipulation
CVSS 9.8
CVE-2024-47406
CRITICAL
Sharp and Toshiba Tec MFPs - Auth Bypass
CVSS 9.1
CVE-2024-48442
MEDIUM
Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-...
CVSS 6.5
CVE-2024-47902
HIGH
InterMesh 7177 Hybrid 2.0 < 8.2.12 & 7707 Fire < 7.2.12 - Unauthenticated OS Command Execution
CVSS 7.2
CVE-2024-47575
CRITICAL
KEV
Fortinet FortiManager <7.6.0 - RCE
CVSS 9.8
CVE-2024-26519
CRITICAL
Casa Systems NTC-221 <2.0.99.0 - RCE
CVSS 9.0
CVE-2024-10002
HIGH
Rover IDX <3.0.0.2906 - Auth Bypass
CVSS 8.8
CVE-2024-40091
MEDIUM
Vilo 5 Mesh WiFi System <= 5.16.1.33 - Info Disclosure
CVSS 5.3
CVE-2024-40087
CRITICAL
Vilo 5 Mesh WiFi System <= 5.16.1.33 - Privilege Escalation
CVSS 9.6
CVE-2024-47912
HIGH
Mitel MiCollab < 9.8.1.201 - Unauthenticated Data Access in AWV Conferencing Component
CVSS 8.2
CVE-2024-49604
CRITICAL
Najeeb Ahmad Simple User Registration <5.5 - Auth Bypass
CVSS 9.8
CVE-2024-49328
CRITICAL
WP REST API FNS <= 1.0.0 - Authentication Bypass
CVSS 9.8
CVE-2024-49399
HIGH
Elvaco M-Bus Metering Gateway CMe3100 1.12.1 - Missing Authentication for Critical Function
CVE-2024-48920
CRITICAL
PutongOJ <2.1.0-beta.1 - Privilege Escalation
CVSS 9.1
CVE-2024-9861
HIGH
Miniorange OTP Verification with Firebase <= 3.6.0 - Unauthenticated Authentication Bypass via OTP Login Token
CVSS 8.1
CVE-2024-45844
HIGH
F5 BIG-IP 15.1.0-15.1.10.5 - Unauthenticated Access Control Bypass via Monitor Functionality
CVSS 7.2
CVE-2024-21272
HIGH
MySQL Connector/Python <= 9.0.0 - Authenticated Remote Takeover via Multiple Protocols
CVSS 7.5
CVE-2024-5749
HIGH
HP DesignJet Firmware < 001.2419b - Unauthenticated SMTP Credential Exposure
CVSS 7.5
CVE-2024-45276
HIGH
Helmholz REX 100 and mbCONNECTLINE mbNET.mini Firmware <= 2.3.1 - Unauthenticated File Read
CVSS 7.5
CVE-2024-45274
CRITICAL
Helmholz REX 100 and MBConnectLine MBnet.mini Firmware <= 2.3.1 - OS Command Execution via UDP
CVSS 9.8
CVE-2024-9984
CRITICAL
Enterprise Cloud Database - Info Disclosure
CVSS 9.8
Details
Vulnerabilities
2,428
Exploit Likelihood
High