CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,205 vulnerabilities with CWE-306
CVE-2026-25192
CRITICAL
CTEK Chargeportal Missing Authentication for Critical Function
CVSS 9.4
CVE-2026-22898
CRITICAL
QNAP QVR Pro < 2.7.4.14 - Missing Authentication for Critical Function
CVSS 9.8
CVE-2026-33070
LOW
FileRise has Unauthenticated Share Link Deletion
CVSS 3.7
CVE-2026-4476
MEDIUM
Yi Technology YI Home Camera CGI Endpoint ipc missing authentication
CVSS 6.3
CVE-2026-33038
HIGH
AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments
CVSS 8.1
CVE-2026-33017
CRITICAL
KEV
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
CVSS 9.8
CVE-2026-21992
CRITICAL
Oracle Identity Manager 12.2.1.4.0 - RCE
CVSS 9.8
CVE-2026-32985
CRITICAL
Xerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution
CVSS 9.8
CVE-2026-22731
HIGH
Authentication Bypass under Actuator Health groups paths
CVSS 8.2
CVE-2026-32041
MEDIUM
OpenClaw < 2026.3.1 - Unauthenticated Browser Control Access via Failed Auth Bootstrap
CVSS 6.9
CVE-2026-24062
HIGH
Insufficient XPC Client validation leading to local privilege escalation in Arturia Software Center
CVSS 7.8
CVE-2026-2603
HIGH
Keycloak: keycloak: unauthorized authentication via disabled saml identity provider
CVSS 8.1
CVE-2026-22174
MEDIUM
OpenClaw < 2026.2.22 - Gateway Token Disclosure via Chrome CDP Probe
CVSS 6.8
CVE-2026-22727
HIGH
Cloud Foundry unprotected internal endpoints
CVSS 7.5
CVE-2026-1264
HIGH
IBM Sterling B2B Integrator and IBM Sterling File Gateway Improper Access Controls
CVSS 7.1
CVE-2026-3207
CRITICAL
TIBCO BPM Enterprise Remote Code Execution (RCE) Vulnerability
CVSS 9.8
CVE-2026-32297
HIGH
Angeet ES3 KVM unauthenticated arbitrary file write
CVSS 7.5
CVE-2026-32296
HIGH
Sipeed NanoKVM unauthenticated Wi-Fi configuration endpoint
CVSS 8.2
CVE-2026-32291
MEDIUM
GL-iNet Comet (GL-RM1) KVM unauthenticated root access via UART serial console
CVSS 6.8
CVE-2026-4312
CRITICAL
DrangSoft|GCB/FCB Audit Software - Missing Authentication
CVSS 9.8
CVE-2026-4187
MEDIUM
Tiandy Easy7 7.17.0 - Auth Bypass
CVSS 5.3
CVE-2026-3558
HIGH
Philips Hue Bridge - Auth Bypass
CVSS 8.1
CVE-2026-32594
HIGH
Parse Server GraphQL WebSocket endpoint bypasses security middleware
CVSS 7.3
CVE-2026-2491
MEDIUM
Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability
CVSS 6.3
CVE-2026-20995
MEDIUM
Samsung Mobile Smart Switch - Auth Bypass
CVSS 5.3
Details
Vulnerabilities
2,205
Exploit Likelihood
High