CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,438 vulnerabilities with CWE-306
CVE-2021-41418
CRITICAL
AriaNg 0.1.0-1.2.2 - Unauthenticated Incorrect Access Control
CVSS 9.8
CVE-2021-42893
HIGH
TOTOLINK EX1200T V4.1.2cu.5215 - Unauthenticated Sensitive Information Exposure via getSysStatusCfg
CVSS 7.5
CVE-2021-42891
HIGH
TOTOLINK EX1200T V4.1.2cu.5215 - Unauthenticated Sensitive Information Disclosure
CVSS 7.5
CVE-2021-42889
HIGH
TOTOLINK EX1200T V4.1.2cu.5215 - Unauthenticated Sensitive Information Exposure
CVSS 7.5
CVE-2021-25094
HIGH
Tatsu Wordpress Plugin RCE
CVSS 8.1
CVE-2021-43483
HIGH
CLARO KAON CG3000 <1.00.67 - Info Disclosure
CVSS 8.0
CVE-2021-33008
HIGH
AVEVA System Platform <2020 R2 P01 - Auth Bypass
CVSS 8.8
CVE-2021-20238
LOW
OpenShift Container Platform - Unauthenticated Sensitive Data Exposure via Machine Config Server Endpoint
CVSS 3.7
CVE-2021-46009
CRITICAL
Totolink A3100R V5.9c.4577 - Info Disclosure
CVSS 9.8
CVE-2021-46006
MEDIUM
Totolink A3100R V5.9c.4577 - Unauthenticated Configuration Modification via test.asp
CVSS 6.5
CVE-2021-3589
HIGH
Foreman Ansible - Privilege Escalation
CVSS 8.0
CVE-2021-45878
CRITICAL
GARO Wallbox GLB/GTB/GTC Firmware < 185 - Unauthenticated Incorrect Access Control
CVSS 9.1
CVE-2021-44262
HIGH
Netgear WAC104 < 1.0.4.13 - Unauthenticated Information Exposure via MNU_top.htm
CVSS 7.5
CVE-2021-44261
MEDIUM
Netgear WAC104 < 1.0.4.13 - Unauthenticated Information Exposure via BRS_top.html
CVSS 5.3
CVE-2021-44260
HIGH
WAVLINK AC1200 WAVLINK-A42W-1.27.6-20180418 - Unauthenticated Information Disclosure via live_mfg.html
CVSS 7.5
CVE-2021-44259
CRITICAL
WAVLINK AC1200 WAVLINK-A42W-1.27.6-20180418 - Unauthenticated Access via wx.html Page
CVSS 9.8
CVE-2021-33658
HIGH
atune <0.3-0.8 - Privilege Escalation
CVSS 7.8
CVE-2021-46384
CRITICAL
MCMS <=5.2.5 - Unauthenticated Remote Code Execution via Freemarker Template Utility
CVSS 9.8
CVE-2021-46371
HIGH
antd-admin <5.5.0 - Info Disclosure
CVSS 7.5
CVE-2021-45420
CRITICAL
Emerson Dixell XWEB-500 Firmware - Unauthenticated Arbitrary File Write via logo_extra_upload.cgi
CVSS 9.8
CVE-2021-22823
CRITICAL
IGSS dc.exe <15.0.0.21320 - Missing Authentication
CVSS 9.1
CVE-2021-22805
CRITICAL
IGSS dc.exe <15.0.0.21243 - Missing Authentication
CVSS 9.1
CVE-2021-31814
MEDIUM
Stormshield Network Security 1.1.0 2.1.0-2.9.0 - Missing Authentication for Critical Function
CVSS 6.1
CVE-2021-21964
HIGH
Sealevel SeaConnect 370W Firmware 1.3.34 - Denial of Service via Modbus Configuration
CVSS 7.4
CVE-2021-44255
HIGH
MotionEye <= 0.42.1 and MotionEyeOS <= 20200606 - Authenticated Remote Code Execution via Malicious Configuration Backup
CVSS 7.2
Details
Vulnerabilities
2,438
Exploit Likelihood
High