CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,438 vulnerabilities with CWE-306
CVE-2022-26303
HIGH
Open Automation Software OAS Platform <16.00.0112 - Info Disclosure
CVSS 7.5
CVE-2022-26082
CRITICAL
Open Automation Software OAS Platform <16.00.0112 - RCE
CVSS 9.1
CVE-2022-26067
MEDIUM
Open Automation Software OAS Platform <16.00.0112 - Info Disclosure
CVSS 4.9
CVE-2022-26043
HIGH
Open Automation Software OAS Platform <16.00.0112 - Info Disclosure
CVSS 7.5
CVE-2022-26026
HIGH
Open Automation Software OAS Platform <16.00.0112 - DoS
CVSS 7.5
CVE-2022-29402
MEDIUM
TP-Link TL-WR840N EU <6.20 - Privilege Escalation
CVSS 6.8
CVE-2022-22309
MEDIUM
POWER systems FSP - Unauthenticated Login
CVSS 6.8
CVE-2022-28660
CRITICAL
Grafana Enterprise Logs <1.4.0 - Info Disclosure
CVSS 9.8
CVE-2022-29883
MEDIUM
Siemens 7kg8500-0aa00-0aa0 Firmware < 3.00 - Missing Authentication
CVSS 5.3
CVE-2022-29881
MEDIUM
Siemens 7kg8500-0aa00-0aa0 Firmware < 3.00 - Missing Authentication
CVSS 5.3
CVE-2022-29879
MEDIUM
Siemens 7kg8500-0aa00-0aa0 Firmware < 3.00 - Missing Authentication
CVSS 4.3
CVE-2022-29877
MEDIUM
Siemens 7kg8500-0aa00-0aa0 Firmware < 3.00 - Missing Authentication
CVSS 6.5
CVE-2022-26925
HIGH
KEV
Windows - Unauthenticated Remote Code Execution via LSA Spoofing
CVSS 8.1
CVE-2022-0424
MEDIUM
The Popup by Supsystic WordPress <1.10.9 - Info Disclosure
CVSS 5.3
CVE-2022-27495
MEDIUM
F5 NGINX Service Mesh 1.3.x - Missing Authentication for Critical Function
CVSS 6.5
CVE-2022-1388
CRITICAL
KEV
F5 BIG-IP iControl RCE via REST Authentication Bypass
CVSS 9.8
CVE-2022-1300
CRITICAL
TRUMPF TruTops Boost 13.01-13.05 and TruTops Fab/Monitor 22.01-22.05 - Unauthenticated Critical Function Access
CVSS 9.8
CVE-2022-29934
HIGH
USU Oracle Optimization < 5.17.5 - Unauthenticated Privilege Escalation via pkexec
CVSS 7.8
CVE-2022-24935
HIGH
Lexmark Firmware < 2022-02-10 - Unauthenticated Incorrect Access Control
CVSS 7.5
CVE-2022-28719
CRITICAL
AssetView < 13.2.0 - Unauthenticated Arbitrary Code Execution via Crafted Configuration File Upload
CVSS 9.8
CVE-2022-27332
CRITICAL
Zammad < 5.1.0 - Unauthenticated CTI Caller Log Entry Injection
CVSS 9.1
CVE-2022-0993
HIGH
SiteGround Security < 1.2.5 - Unauthenticated Authentication Bypass via 2FA Backup Code
CVSS 8.1
CVE-2022-0992
CRITICAL
SiteGround Security Optimizer <= 1.2.5 - Unauthenticated Authentication Bypass via 2FA Setup
CVSS 9.8
CVE-2022-0878
MEDIUM
Combined Charging System Firmware < 2.0 - Unauthenticated Denial of Service via Electromagnetic Interference
CVSS 4.6
CVE-2022-0140
MEDIUM
Visual Form Builder <3.0.6 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
2,438
Exploit Likelihood
High