CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,430 vulnerabilities with CWE-306
CVE-2024-1076
MEDIUM
SSL Zen < 4.6.0 - Unauthenticated Private Key Exposure via Directory Listing
CVSS 6.5
CVE-2024-2860
HIGH
Brocade SANnav < 2.3.0a - Unauthenticated PostgreSQL Database Access
CVSS 7.8
CVE-2024-3661
HIGH
FortiClient 6.4.0-7.2.4 - Unauthenticated VPN Traffic Leak via DHCP Classless Static Route Option
CVSS 7.6
CVE-2024-32764
CRITICAL
myQNAPcloud Link <2.4.51 - Privilege Escalation
CVSS 9.9
CVE-2024-21846
MEDIUM
Electrolink Compact DAB and FM Transmitters - Denial of Service via Crafted GET Request
CVSS 5.3
CVE-2024-1491
HIGH
Electrolink Compact DAB Transmitter - Unauthenticated Arbitrary Code Execution via MPFS File System Binary Image Upload
CVSS 7.5
CVE-2024-21014
CRITICAL
Oracle Hospitality Simphony 19.1.0-19.5.4 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2024-21007
HIGH
Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0 - Unauthenticated Critical Function Access via T3/IIOP
CVSS 7.5
CVE-2024-21006
HIGH
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Unauthenticated Unauthorized Data Access via T3, IIOP
CVSS 7.5
CVE-2024-3701
CRITICAL
Tecno HIOS - Improper Authentication in System Application Component
CVSS 9.8
CVE-2024-3777
CRITICAL
Ai3 QbiBot - Unauthenticated Password Reset via Password Reset Feature
CVSS 9.8
CVE-2024-3774
MEDIUM
aEnrich a+HRD - Unauthenticated Sensitive Information Exposure via System Configuration Parameter
CVSS 5.3
CVE-2024-30391
MEDIUM
Juniper Junos OS Unauthenticated Missing Authentication in Packet Forwarding Engine
CVSS 4.8
CVE-2024-26235
HIGH
Windows Server 2022 23H2 < 10.0.25398.830 - Elevation of Privilege via Windows Update Stack
CVSS 7.8
CVE-2024-3281
HIGH
HP Poly CCX 350/400/500/505/600/700 >=8.0.2.3267 <8.1.3.1301 - Unauthenticated Critical Function Access
CVSS 8.8
CVE-2024-31218
CRITICAL
Webhood <0.9.0 - Missing Authentication
CVSS 9.8
CVE-2024-2921
CRITICAL
Dovolations Server <2024.1.10.0 - Privilege Escalation
CVSS 9.8
CVE-2024-28179
CRITICAL
Jupyter Server Proxy < 3.2.3 and 4.0.0-4.1.1 - Unauthenticated Remote Code Execution via WebSocket Endpoint
CVSS 9.0
CVE-2024-24578
CRITICAL
RaspberryMatic unauthenticated Remote Code Execution vulnerability through HMServer File Upload.
CVSS 10.0
CVE-2024-21824
MEDIUM
Brother Industries - Privilege Escalation
CVSS 5.3
CVE-2024-22513
MEDIUM
djangorestframework-simplejwt <5.3.1 - Info Disclosure
CVSS 5.5
CVE-2024-2450
HIGH
Mattermost <8.1.10, <9.2.6, <9.3.2, <9.4.3 - Privilege Escalation
CVSS 8.8
CVE-2024-27758
HIGH
RPyC 4.0.0-5.9.9 - Remote Code Execution via __array__ Attribute
CVSS 8.4
CVE-2024-2076
MEDIUM
CodeAstro House Rental Management System 1.0 - Missing Authentication in booking.php/owner.php/tenant.php
CVSS 5.3
CVE-2024-26263
MEDIUM
EBM Technologies RISWEB 1.0-3.0 - Unauthenticated Sensitive Data Exposure via Unprotected URL Path
CVSS 5.3
Details
Vulnerabilities
2,430
Exploit Likelihood
High