CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,428 vulnerabilities with CWE-306
CVE-2024-48791 HIGH
Plug n Play Camera com.starvedia.mCamView.zwave <5.5.1 - Info Discl...
CVSS 7.5
CVE-2024-9137 CRITICAL
Moxa EDR-8010 Series < 3.12.1 - Unauthenticated Missing Authentication for Critical Function
CVSS 9.4
CVE-2024-48777 HIGH
LEDVANCE Smartplus EU <2.1.10 - Info Disclosure
CVSS 7.5
CVE-2024-48776 HIGH
Shelly com.home.shelly <1.0.4 - Info Disclosure
CVSS 7.5
CVE-2024-48775 HIGH
Plug n Play Camera com.ezset.delaney 1.2.0 - Info Disclosure
CVSS 7.5
CVE-2024-48774 HIGH
Fermax Asia Pacific Pte Ltd com.fermax.vida <2.4.6 - Info Disclosure
CVSS 7.5
CVE-2024-48773 HIGH
WoFit 7.2.3 - Sensitive Information Exposure via Firmware Update Process
CVSS 7.5
CVE-2024-48771 HIGH
Almando Play APP <1.8.2 - Info Disclosure
CVSS 7.5
CVE-2024-48768 HIGH
appinventor.ai_google.almando_control <2.3.1 - Info Disclosure
CVSS 7.5
CVE-2024-8530 MEDIUM
Missing Authentication - Info Disclosure
CVSS 5.9
CVE-2024-9164 CRITICAL
GitLab 12.5.0-17.2.8, 17.3.0-17.3.4, 17.4.0-17.4.1 - Unauthenticated Pipeline Execution on Arbitrary Branches
CVSS 9.6
CVE-2024-9522 HIGH
WP Users Masquerade <= 2.0.0 - Authenticated Authentication Bypass via ajax_masq_login Function
CVSS 8.8
CVE-2024-43488 HIGH
Visual Studio Code Arduino Extension - Unauthenticated Remote Code Execution
CVSS 8.8
CVE-2024-8943 CRITICAL
LatePoint Plugin <= 5.0.12 - Unauthenticated Authentication Bypass via User ID
CVSS 9.8
CVE-2024-47555 HIGH
User & System Configuration - Info Disclosure
CVSS 8.3
CVE-2024-41988 CRITICAL
TEM Opera Plus FM Family Transmitter - RCE
CVE-2024-35294 MEDIUM
Device Traffic Capture - Info Disclosure
CVSS 6.5
CVE-2024-35293 CRITICAL
Unknown Device - Unauthenticated RCE
CVSS 9.1
CVE-2024-9289 CRITICAL
WordPress WooCommerce Affiliate Program <= 8.4.1 - Authentication Bypass
CVSS 9.8
CVE-2024-42017 CRITICAL
Atos Eviden iCare <2.7.11 - Privilege Escalation
CVSS 10.0
CVE-2024-46293 CRITICAL
Sourcecodester Online Medicine Ordering System 1.0 - Unauthenticated Incorrect Access Control
CVSS 9.8
CVE-2024-8456 CRITICAL
PLANET Technology - Unauthenticated RCE
CVSS 9.8
CVE-2024-39364 MEDIUM
Advantech ADAM-5630 - Command Injection
CVSS 6.3
CVE-2024-8310 CRITICAL
OPW Fuel Management Systems SiteSentinel - Auth Bypass
CVSS 9.8
CVE-2024-6981 CRITICAL
OMNTEC Proteus Tank Monitoring OEL8000III Series - Auth Bypass
CVSS 9.8
Details
Vulnerabilities 2,428
Exploit Likelihood High