CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,343 vulnerabilities with CWE-306
CVE-2026-34279
CRITICAL
Oracle Enterprise Manager Base Platform 13.5 - Privilege Escalation
CVSS 9.1
CVE-2026-34275
CRITICAL
Oracle Advanced Inbound Telephony 12.2.3-12.2.15 - Product Takeover
CVSS 9.8
CVE-2026-34266
MEDIUM
Oracle PeopleSoft Enterprise HCM Absence Management 9.2 - Privilege Escalation
CVSS 6.5
CVE-2026-40884
CRITICAL
goshs: Empty-username SFTP password authentication bypass in goshs
CVSS 9.8
CVE-2026-40050
CRITICAL
CrowdStrike LogScale Unauthenticated Path Traversal
CVSS 9.8
CVE-2026-24177
HIGH
NVIDIA KAI Scheduler < 0.13.0 - Unauthenticated Information Disclosure via API Endpoints
CVSS 7.7
CVE-2026-41039
HIGH
Information Disclosure Vulnerability in Quantum Networks Router QN-I-470
CVSS 7.5
CVE-2026-34839
MEDIUM
Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
CVSS 6.5
CVE-2026-26944
HIGH
Dell PowerProtect Data Domain 7.7.1.0-8.6 - Auth Bypass
CVSS 8.8
CVE-2026-25058
HIGH
Vexa's unauthenticated internal transcript endpoint exposed by default
CVSS 7.5
CVE-2026-6369
MEDIUM
Exposed Session Token in canonical-livepatch client snap
CVSS 5.5
CVE-2026-32962
MEDIUM
silex technology SD-330AC <=Ver.1.42 - Auth Bypass
CVSS 5.3
CVE-2026-32957
MEDIUM
silex technology SD-330AC <=Ver.1.42 - Auth Bypass
CVSS 5.3
CVE-2026-6588
MEDIUM
serge-chat serge Model API Endpoint model.py delete_model missing authentication
CVSS 6.5
CVE-2026-6582
HIGH
TransformerOptimus SuperAGI Vector Database Management Endpoint vector_dbs.py get_vector_db_details missing authentication
CVSS 7.3
CVE-2026-6579
MEDIUM
liangliangyy DjangoBlog Clean Endpoint views.py missing authentication
CVSS 6.5
CVE-2026-6577
HIGH
liangliangyy DjangoBlog logtracks Endpoint views.py missing authentication
CVSS 7.3
CVE-2026-40461
HIGH
Anviz Products Missing Authentication for Critical Function
CVSS 7.5
CVE-2026-35546
CRITICAL
Anviz Products Missing Authentication for Critical Function
CVSS 9.8
CVE-2026-6348
HIGH
Simopro Technology|WinMatrix - Missing Authentication
CVSS 8.8
CVE-2026-34160
HIGH
Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services
CVSS 8.6
CVE-2026-33715
HIGH
Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action
CVSS 7.2
CVE-2026-26160
HIGH
Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-26159
HIGH
Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-40289
CRITICAL
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
CVSS 9.1
Details
Vulnerabilities
2,343
Exploit Likelihood
High