CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,435 vulnerabilities with CWE-306
CVE-2023-22087 HIGH
Oracle Hospitality Applications <5.6 - RCE
CVSS 8.8
CVE-2023-22072 CRITICAL
Oracle WebLogic Server <12.2.1.3.0 - RCE
CVSS 9.8
CVE-2023-22069 CRITICAL
Oracle WebLogic Server <14.1.1.0.0 - RCE
CVSS 9.8
CVE-2023-44116 CRITICAL
HarmonyOS - Missing Authentication for Critical Function in APPWidget Module
CVSS 9.8
CVE-2023-43271 CRITICAL
70mai a500s <1.2.119 - Info Disclosure
CVSS 9.1
CVE-2023-4884 MEDIUM
open5gs < 2.4.10 - Unauthenticated Information Disclosure via HTTP Endpoint
CVSS 6.5
CVE-2023-4506 LOW
WordPress <4.1.10 - Privilege Escalation
CVSS 2.2
CVE-2023-4505 LOW
Staff / Employee Business Directory <1.2.3 - Privilege Escalation
CVSS 2.2
CVE-2023-44152 CRITICAL
Acronis Cyber Protect <35979 - Info Disclosure
CVSS 9.1
CVE-2023-41333 MEDIUM
Cilium < 1.12.14, 1.14.0-1.14.2 - Unauthenticated Policy Bypass via EndpointSelector DoesNotExist Operator
CVSS 6.9
CVE-2023-36851 MEDIUM KEV
Juniper Networks Junos OS - Unauthenticated File Upload/Download
CVSS 5.3
CVE-2023-43644 CRITICAL
Sing-box <1.4.4, <1.5.0-rc.4 - Auth Bypass
CVSS 9.1
CVE-2023-42793 CRITICAL KEV
JetBrains TeamCity < 2023.05.4 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2023-4702 CRITICAL
Yepas Digital Yepas < 1.0.1 - Authentication Bypass
CVSS 9.8
CVE-2023-4516 HIGH
Schneider Electric IGSS Update Service - Missing Authentication Code Execution
CVSS 7.8
CVE-2023-41367 MEDIUM
SAP NetWeaver <7.50 - Info Disclosure
CVSS 5.3
CVE-2023-4815 HIGH
GitHub answerdev/answer <1.1.3 - Info Disclosure
CVSS 8.8
CVE-2023-31132 HIGH
Cacti <1.2.25 - Privilege Escalation
CVSS 7.8
CVE-2023-39981 HIGH
MXsecurity < 1.0.1 - Unauthenticated Information Disclosure via Inadequate Authentication
CVSS 7.5
CVE-2023-34392 HIGH
SEL-5037 SEL Grid Configurator < 4.5.0.20 - Unauthenticated Remote Command Execution
CVSS 8.2
CVE-2023-40598 HIGH
Splunk Enterprise <8.2.12, 9.0.6, 9.1.1 - Code Injection
CVSS 8.5
CVE-2023-40170 MEDIUM
jupyter_server < 2.7.2 - Improper Access Control in Files Endpoint
CVSS 4.6
CVE-2023-38030 HIGH
Saho ADM100 and ADM-100FP - Unauthenticated Remote Code Execution via Website URL
CVSS 7.5
CVE-2023-38028 CRITICAL
Saho ADM100 and ADM-100FP - Unauthenticated Information Disclosure and Data Manipulation
CVSS 9.1
CVE-2023-40585 HIGH
Ironic-image <capm3-v1.4.3 - Info Disclosure
CVSS 7.3
Details
Vulnerabilities 2,435
Exploit Likelihood High