CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,430 vulnerabilities with CWE-306
CVE-2024-1076 MEDIUM
SSL Zen < 4.6.0 - Unauthenticated Private Key Exposure via Directory Listing
CVSS 6.5
CVE-2024-2860 HIGH
Brocade SANnav < 2.3.0a - Unauthenticated PostgreSQL Database Access
CVSS 7.8
CVE-2024-3661 HIGH
FortiClient 6.4.0-7.2.4 - Unauthenticated VPN Traffic Leak via DHCP Classless Static Route Option
CVSS 7.6
CVE-2024-32764 CRITICAL
myQNAPcloud Link <2.4.51 - Privilege Escalation
CVSS 9.9
CVE-2024-21846 MEDIUM
Electrolink Compact DAB and FM Transmitters - Denial of Service via Crafted GET Request
CVSS 5.3
CVE-2024-1491 HIGH
Electrolink Compact DAB Transmitter - Unauthenticated Arbitrary Code Execution via MPFS File System Binary Image Upload
CVSS 7.5
CVE-2024-21014 CRITICAL
Oracle Hospitality Simphony 19.1.0-19.5.4 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2024-21007 HIGH
Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0 - Unauthenticated Critical Function Access via T3/IIOP
CVSS 7.5
CVE-2024-21006 HIGH
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Unauthenticated Unauthorized Data Access via T3, IIOP
CVSS 7.5
CVE-2024-3701 CRITICAL
Tecno HIOS - Improper Authentication in System Application Component
CVSS 9.8
CVE-2024-3777 CRITICAL
Ai3 QbiBot - Unauthenticated Password Reset via Password Reset Feature
CVSS 9.8
CVE-2024-3774 MEDIUM
aEnrich a+HRD - Unauthenticated Sensitive Information Exposure via System Configuration Parameter
CVSS 5.3
CVE-2024-30391 MEDIUM
Juniper Junos OS Unauthenticated Missing Authentication in Packet Forwarding Engine
CVSS 4.8
CVE-2024-26235 HIGH
Windows Server 2022 23H2 < 10.0.25398.830 - Elevation of Privilege via Windows Update Stack
CVSS 7.8
CVE-2024-3281 HIGH
HP Poly CCX 350/400/500/505/600/700 >=8.0.2.3267 <8.1.3.1301 - Unauthenticated Critical Function Access
CVSS 8.8
CVE-2024-31218 CRITICAL
Webhood <0.9.0 - Missing Authentication
CVSS 9.8
CVE-2024-2921 CRITICAL
Dovolations Server <2024.1.10.0 - Privilege Escalation
CVSS 9.8
CVE-2024-28179 CRITICAL
Jupyter Server Proxy < 3.2.3 and 4.0.0-4.1.1 - Unauthenticated Remote Code Execution via WebSocket Endpoint
CVSS 9.0
CVE-2024-24578 CRITICAL
RaspberryMatic unauthenticated Remote Code Execution vulnerability through HMServer File Upload.
CVSS 10.0
CVE-2024-21824 MEDIUM
Brother Industries - Privilege Escalation
CVSS 5.3
CVE-2024-22513 MEDIUM
djangorestframework-simplejwt <5.3.1 - Info Disclosure
CVSS 5.5
CVE-2024-2450 HIGH
Mattermost <8.1.10, <9.2.6, <9.3.2, <9.4.3 - Privilege Escalation
CVSS 8.8
CVE-2024-27758 HIGH
RPyC 4.0.0-5.9.9 - Remote Code Execution via __array__ Attribute
CVSS 8.4
CVE-2024-2076 MEDIUM
CodeAstro House Rental Management System 1.0 - Missing Authentication in booking.php/owner.php/tenant.php
CVSS 5.3
CVE-2024-26263 MEDIUM
EBM Technologies RISWEB 1.0-3.0 - Unauthenticated Sensitive Data Exposure via Unprotected URL Path
CVSS 5.3
Details
Vulnerabilities 2,430
Exploit Likelihood High