CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,435 vulnerabilities with CWE-306
CVE-2023-22087
HIGH
Oracle Hospitality Applications <5.6 - RCE
CVSS 8.8
CVE-2023-22072
CRITICAL
Oracle WebLogic Server <12.2.1.3.0 - RCE
CVSS 9.8
CVE-2023-22069
CRITICAL
Oracle WebLogic Server <14.1.1.0.0 - RCE
CVSS 9.8
CVE-2023-44116
CRITICAL
HarmonyOS - Missing Authentication for Critical Function in APPWidget Module
CVSS 9.8
CVE-2023-43271
CRITICAL
70mai a500s <1.2.119 - Info Disclosure
CVSS 9.1
CVE-2023-4884
MEDIUM
open5gs < 2.4.10 - Unauthenticated Information Disclosure via HTTP Endpoint
CVSS 6.5
CVE-2023-4506
LOW
WordPress <4.1.10 - Privilege Escalation
CVSS 2.2
CVE-2023-4505
LOW
Staff / Employee Business Directory <1.2.3 - Privilege Escalation
CVSS 2.2
CVE-2023-44152
CRITICAL
Acronis Cyber Protect <35979 - Info Disclosure
CVSS 9.1
CVE-2023-41333
MEDIUM
Cilium < 1.12.14, 1.14.0-1.14.2 - Unauthenticated Policy Bypass via EndpointSelector DoesNotExist Operator
CVSS 6.9
CVE-2023-36851
MEDIUM
KEV
Juniper Networks Junos OS - Unauthenticated File Upload/Download
CVSS 5.3
CVE-2023-43644
CRITICAL
Sing-box <1.4.4, <1.5.0-rc.4 - Auth Bypass
CVSS 9.1
CVE-2023-42793
CRITICAL
KEV
JetBrains TeamCity < 2023.05.4 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2023-4702
CRITICAL
Yepas Digital Yepas < 1.0.1 - Authentication Bypass
CVSS 9.8
CVE-2023-4516
HIGH
Schneider Electric IGSS Update Service - Missing Authentication Code Execution
CVSS 7.8
CVE-2023-41367
MEDIUM
SAP NetWeaver <7.50 - Info Disclosure
CVSS 5.3
CVE-2023-4815
HIGH
GitHub answerdev/answer <1.1.3 - Info Disclosure
CVSS 8.8
CVE-2023-31132
HIGH
Cacti <1.2.25 - Privilege Escalation
CVSS 7.8
CVE-2023-39981
HIGH
MXsecurity < 1.0.1 - Unauthenticated Information Disclosure via Inadequate Authentication
CVSS 7.5
CVE-2023-34392
HIGH
SEL-5037 SEL Grid Configurator < 4.5.0.20 - Unauthenticated Remote Command Execution
CVSS 8.2
CVE-2023-40598
HIGH
Splunk Enterprise <8.2.12, 9.0.6, 9.1.1 - Code Injection
CVSS 8.5
CVE-2023-40170
MEDIUM
jupyter_server < 2.7.2 - Improper Access Control in Files Endpoint
CVSS 4.6
CVE-2023-38030
HIGH
Saho ADM100 and ADM-100FP - Unauthenticated Remote Code Execution via Website URL
CVSS 7.5
CVE-2023-38028
CRITICAL
Saho ADM100 and ADM-100FP - Unauthenticated Information Disclosure and Data Manipulation
CVSS 9.1
CVE-2023-40585
HIGH
Ironic-image <capm3-v1.4.3 - Info Disclosure
CVSS 7.3
Details
Vulnerabilities
2,435
Exploit Likelihood
High