CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,439 vulnerabilities with CWE-306
CVE-2021-37415 CRITICAL KEV
Zoho ManageEngine ServiceDesk Plus < 11302 - Unauthenticated Authentication Bypass via REST-API URLs
CVSS 9.8
CVE-2021-27668 MEDIUM
HashiCorp Vault Enterprise <1.6.2 - Info Disclosure
CVSS 5.3
CVE-2021-33882 MEDIUM
B. Braun SpaceCom2 < 012U000062 - Unauthenticated Device Reconfiguration via Proprietary Networking Commands
CVSS 6.8
CVE-2021-39144 HIGH KEV
XStream < 1.4.18 - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.5
CVE-2021-31868 MEDIUM
Rapid7 Nexpose < 6.6.96 - Authenticated Insecure Direct Object Reference in Legacy Ticketing Feature
CVSS 4.3
CVE-2021-35936 MEDIUM
Apache Airflow < 2.1.2 - Info Disclosure
CVSS 5.3
CVE-2021-37697 HIGH
tmerc-cogs < 3.0 - Unauthenticated Sensitive Information Exposure via Membership Event Message
CVSS 7.1
CVE-2021-37696 HIGH
tmerc-cogs < 3.0 - Unauthenticated Sensitive Information Exposure via MassDM Message
CVSS 7.1
CVE-2021-37843 CRITICAL
Atlassian SAML Single Sign-On < 2.5.9, < 3.5.6, < 3.6.6.1 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2021-32794 MEDIUM
ArchiSteamFarm < 5.1.2.4 - Improper Authentication via IPC Password Removal
CVSS 6.8
CVE-2021-22784 MEDIUM
C-Bus Toolkit <1.15.8 - Auth Bypass
CVSS 5.7
CVE-2021-22772 CRITICAL
Easergy T200 Firmware < SC2-04MOD-07000100 - Unauthenticated Critical Function Access
CVSS 9.8
CVE-2021-36124 CRITICAL
Echo ShareCare <8.15.5 - Info Disclosure
CVSS 9.8
CVE-2021-28809 CRITICAL
QNAP Hybrid Backup Sync < 3.0.210507 - Improper Access Control
CVSS 9.8
CVE-2021-20474 HIGH
IBM Guardium Data Encryption <4.0.0.4 - DoS
CVSS 7.5
CVE-2021-33221 CRITICAL
CommScope Ruckus IoT Controller <1.7.1.0 - Info Disclosure
CVSS 9.8
CVE-2021-34621 CRITICAL
ProfilePress 3.0.0-3.1.3 - Unauthenticated Privilege Escalation via Registration
CVSS 9.8
CVE-2021-20107 MEDIUM
Sloan Optima EAF/EBF Firmware - Unauthenticated BLE Interface Access
CVSS 5.4
CVE-2021-35941 HIGH
Western Digital WD My Book Live - Auth Bypass
CVSS 7.5
CVE-2021-31337 CRITICAL
SINAMICS SL150, SM150, and SM150i Firmware - Unauthenticated Telnet Access
CVSS 9.8
CVE-2021-32709 MEDIUM
Shopware <6.4.1.1 - Info Disclosure
CVSS 4.9
CVE-2021-33346 CRITICAL
D-LINK DSL-2888A - Privilege Escalation
CVSS 9.8
CVE-2021-32700 CRITICAL
Ballerina <1.2.14 - Supply Chain Attack
CVSS 9.1
CVE-2021-32659 MEDIUM
Matrix-appservice-bridge <2.6.0 - Info Disclosure
CVSS 6.5
CVE-2021-32930 CRITICAL
Advantech iView < 5.7.03.6182 - Unauthenticated Arbitrary Code Execution
CVSS 9.8
Details
Vulnerabilities 2,439
Exploit Likelihood High