CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,343 vulnerabilities with CWE-306
CVE-2026-34279 CRITICAL
Oracle Enterprise Manager Base Platform 13.5 - Privilege Escalation
CVSS 9.1
CVE-2026-34275 CRITICAL
Oracle Advanced Inbound Telephony 12.2.3-12.2.15 - Product Takeover
CVSS 9.8
CVE-2026-34266 MEDIUM
Oracle PeopleSoft Enterprise HCM Absence Management 9.2 - Privilege Escalation
CVSS 6.5
CVE-2026-40884 CRITICAL
goshs: Empty-username SFTP password authentication bypass in goshs
CVSS 9.8
CVE-2026-40050 CRITICAL
CrowdStrike LogScale Unauthenticated Path Traversal
CVSS 9.8
CVE-2026-24177 HIGH
NVIDIA KAI Scheduler < 0.13.0 - Unauthenticated Information Disclosure via API Endpoints
CVSS 7.7
CVE-2026-41039 HIGH
Information Disclosure Vulnerability in Quantum Networks Router QN-I-470
CVSS 7.5
CVE-2026-34839 MEDIUM
Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
CVSS 6.5
CVE-2026-26944 HIGH
Dell PowerProtect Data Domain 7.7.1.0-8.6 - Auth Bypass
CVSS 8.8
CVE-2026-25058 HIGH
Vexa's unauthenticated internal transcript endpoint exposed by default
CVSS 7.5
CVE-2026-6369 MEDIUM
Exposed Session Token in canonical-livepatch client snap
CVSS 5.5
CVE-2026-32962 MEDIUM
silex technology SD-330AC <=Ver.1.42 - Auth Bypass
CVSS 5.3
CVE-2026-32957 MEDIUM
silex technology SD-330AC <=Ver.1.42 - Auth Bypass
CVSS 5.3
CVE-2026-6588 MEDIUM
serge-chat serge Model API Endpoint model.py delete_model missing authentication
CVSS 6.5
CVE-2026-6582 HIGH
TransformerOptimus SuperAGI Vector Database Management Endpoint vector_dbs.py get_vector_db_details missing authentication
CVSS 7.3
CVE-2026-6579 MEDIUM
liangliangyy DjangoBlog Clean Endpoint views.py missing authentication
CVSS 6.5
CVE-2026-6577 HIGH
liangliangyy DjangoBlog logtracks Endpoint views.py missing authentication
CVSS 7.3
CVE-2026-40461 HIGH
Anviz Products Missing Authentication for Critical Function
CVSS 7.5
CVE-2026-35546 CRITICAL
Anviz Products Missing Authentication for Critical Function
CVSS 9.8
CVE-2026-6348 HIGH
Simopro Technology|WinMatrix - Missing Authentication
CVSS 8.8
CVE-2026-34160 HIGH
Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services
CVSS 8.6
CVE-2026-33715 HIGH
Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action
CVSS 7.2
CVE-2026-26160 HIGH
Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-26159 HIGH
Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-40289 CRITICAL
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
CVSS 9.1
Details
Vulnerabilities 2,343
Exploit Likelihood High