CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,438 vulnerabilities with CWE-306
CVE-2022-26303 HIGH
Open Automation Software OAS Platform <16.00.0112 - Info Disclosure
CVSS 7.5
CVE-2022-26082 CRITICAL
Open Automation Software OAS Platform <16.00.0112 - RCE
CVSS 9.1
CVE-2022-26067 MEDIUM
Open Automation Software OAS Platform <16.00.0112 - Info Disclosure
CVSS 4.9
CVE-2022-26043 HIGH
Open Automation Software OAS Platform <16.00.0112 - Info Disclosure
CVSS 7.5
CVE-2022-26026 HIGH
Open Automation Software OAS Platform <16.00.0112 - DoS
CVSS 7.5
CVE-2022-29402 MEDIUM
TP-Link TL-WR840N EU <6.20 - Privilege Escalation
CVSS 6.8
CVE-2022-22309 MEDIUM
POWER systems FSP - Unauthenticated Login
CVSS 6.8
CVE-2022-28660 CRITICAL
Grafana Enterprise Logs <1.4.0 - Info Disclosure
CVSS 9.8
CVE-2022-29883 MEDIUM
Siemens 7kg8500-0aa00-0aa0 Firmware < 3.00 - Missing Authentication
CVSS 5.3
CVE-2022-29881 MEDIUM
Siemens 7kg8500-0aa00-0aa0 Firmware < 3.00 - Missing Authentication
CVSS 5.3
CVE-2022-29879 MEDIUM
Siemens 7kg8500-0aa00-0aa0 Firmware < 3.00 - Missing Authentication
CVSS 4.3
CVE-2022-29877 MEDIUM
Siemens 7kg8500-0aa00-0aa0 Firmware < 3.00 - Missing Authentication
CVSS 6.5
CVE-2022-26925 HIGH KEV
Windows - Unauthenticated Remote Code Execution via LSA Spoofing
CVSS 8.1
CVE-2022-0424 MEDIUM
The Popup by Supsystic WordPress <1.10.9 - Info Disclosure
CVSS 5.3
CVE-2022-27495 MEDIUM
F5 NGINX Service Mesh 1.3.x - Missing Authentication for Critical Function
CVSS 6.5
CVE-2022-1388 CRITICAL KEV
F5 BIG-IP iControl RCE via REST Authentication Bypass
CVSS 9.8
CVE-2022-1300 CRITICAL
TRUMPF TruTops Boost 13.01-13.05 and TruTops Fab/Monitor 22.01-22.05 - Unauthenticated Critical Function Access
CVSS 9.8
CVE-2022-29934 HIGH
USU Oracle Optimization < 5.17.5 - Unauthenticated Privilege Escalation via pkexec
CVSS 7.8
CVE-2022-24935 HIGH
Lexmark Firmware < 2022-02-10 - Unauthenticated Incorrect Access Control
CVSS 7.5
CVE-2022-28719 CRITICAL
AssetView < 13.2.0 - Unauthenticated Arbitrary Code Execution via Crafted Configuration File Upload
CVSS 9.8
CVE-2022-27332 CRITICAL
Zammad < 5.1.0 - Unauthenticated CTI Caller Log Entry Injection
CVSS 9.1
CVE-2022-0993 HIGH
SiteGround Security < 1.2.5 - Unauthenticated Authentication Bypass via 2FA Backup Code
CVSS 8.1
CVE-2022-0992 CRITICAL
SiteGround Security Optimizer <= 1.2.5 - Unauthenticated Authentication Bypass via 2FA Setup
CVSS 9.8
CVE-2022-0878 MEDIUM
Combined Charging System Firmware < 2.0 - Unauthenticated Denial of Service via Electromagnetic Interference
CVSS 4.6
CVE-2022-0140 MEDIUM
Visual Form Builder <3.0.6 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 2,438
Exploit Likelihood High