CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,438 vulnerabilities with CWE-306
CVE-2021-41418 CRITICAL
AriaNg 0.1.0-1.2.2 - Unauthenticated Incorrect Access Control
CVSS 9.8
CVE-2021-42893 HIGH
TOTOLINK EX1200T V4.1.2cu.5215 - Unauthenticated Sensitive Information Exposure via getSysStatusCfg
CVSS 7.5
CVE-2021-42891 HIGH
TOTOLINK EX1200T V4.1.2cu.5215 - Unauthenticated Sensitive Information Disclosure
CVSS 7.5
CVE-2021-42889 HIGH
TOTOLINK EX1200T V4.1.2cu.5215 - Unauthenticated Sensitive Information Exposure
CVSS 7.5
CVE-2021-25094 HIGH
Tatsu Wordpress Plugin RCE
CVSS 8.1
CVE-2021-43483 HIGH
CLARO KAON CG3000 <1.00.67 - Info Disclosure
CVSS 8.0
CVE-2021-33008 HIGH
AVEVA System Platform <2020 R2 P01 - Auth Bypass
CVSS 8.8
CVE-2021-20238 LOW
OpenShift Container Platform - Unauthenticated Sensitive Data Exposure via Machine Config Server Endpoint
CVSS 3.7
CVE-2021-46009 CRITICAL
Totolink A3100R V5.9c.4577 - Info Disclosure
CVSS 9.8
CVE-2021-46006 MEDIUM
Totolink A3100R V5.9c.4577 - Unauthenticated Configuration Modification via test.asp
CVSS 6.5
CVE-2021-3589 HIGH
Foreman Ansible - Privilege Escalation
CVSS 8.0
CVE-2021-45878 CRITICAL
GARO Wallbox GLB/GTB/GTC Firmware < 185 - Unauthenticated Incorrect Access Control
CVSS 9.1
CVE-2021-44262 HIGH
Netgear WAC104 < 1.0.4.13 - Unauthenticated Information Exposure via MNU_top.htm
CVSS 7.5
CVE-2021-44261 MEDIUM
Netgear WAC104 < 1.0.4.13 - Unauthenticated Information Exposure via BRS_top.html
CVSS 5.3
CVE-2021-44260 HIGH
WAVLINK AC1200 WAVLINK-A42W-1.27.6-20180418 - Unauthenticated Information Disclosure via live_mfg.html
CVSS 7.5
CVE-2021-44259 CRITICAL
WAVLINK AC1200 WAVLINK-A42W-1.27.6-20180418 - Unauthenticated Access via wx.html Page
CVSS 9.8
CVE-2021-33658 HIGH
atune <0.3-0.8 - Privilege Escalation
CVSS 7.8
CVE-2021-46384 CRITICAL
MCMS <=5.2.5 - Unauthenticated Remote Code Execution via Freemarker Template Utility
CVSS 9.8
CVE-2021-46371 HIGH
antd-admin <5.5.0 - Info Disclosure
CVSS 7.5
CVE-2021-45420 CRITICAL
Emerson Dixell XWEB-500 Firmware - Unauthenticated Arbitrary File Write via logo_extra_upload.cgi
CVSS 9.8
CVE-2021-22823 CRITICAL
IGSS dc.exe <15.0.0.21320 - Missing Authentication
CVSS 9.1
CVE-2021-22805 CRITICAL
IGSS dc.exe <15.0.0.21243 - Missing Authentication
CVSS 9.1
CVE-2021-31814 MEDIUM
Stormshield Network Security 1.1.0 2.1.0-2.9.0 - Missing Authentication for Critical Function
CVSS 6.1
CVE-2021-21964 HIGH
Sealevel SeaConnect 370W Firmware 1.3.34 - Denial of Service via Modbus Configuration
CVSS 7.4
CVE-2021-44255 HIGH
MotionEye <= 0.42.1 and MotionEyeOS <= 20200606 - Authenticated Remote Code Execution via Malicious Configuration Backup
CVSS 7.2
Details
Vulnerabilities 2,438
Exploit Likelihood High