CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,439 vulnerabilities with CWE-306
CVE-2021-37415
CRITICAL
KEV
Zoho ManageEngine ServiceDesk Plus < 11302 - Unauthenticated Authentication Bypass via REST-API URLs
CVSS 9.8
CVE-2021-27668
MEDIUM
HashiCorp Vault Enterprise <1.6.2 - Info Disclosure
CVSS 5.3
CVE-2021-33882
MEDIUM
B. Braun SpaceCom2 < 012U000062 - Unauthenticated Device Reconfiguration via Proprietary Networking Commands
CVSS 6.8
CVE-2021-39144
HIGH
KEV
XStream < 1.4.18 - Remote Code Execution via Untrusted Data Deserialization
CVSS 8.5
CVE-2021-31868
MEDIUM
Rapid7 Nexpose < 6.6.96 - Authenticated Insecure Direct Object Reference in Legacy Ticketing Feature
CVSS 4.3
CVE-2021-35936
MEDIUM
Apache Airflow < 2.1.2 - Info Disclosure
CVSS 5.3
CVE-2021-37697
HIGH
tmerc-cogs < 3.0 - Unauthenticated Sensitive Information Exposure via Membership Event Message
CVSS 7.1
CVE-2021-37696
HIGH
tmerc-cogs < 3.0 - Unauthenticated Sensitive Information Exposure via MassDM Message
CVSS 7.1
CVE-2021-37843
CRITICAL
Atlassian SAML Single Sign-On < 2.5.9, < 3.5.6, < 3.6.6.1 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2021-32794
MEDIUM
ArchiSteamFarm < 5.1.2.4 - Improper Authentication via IPC Password Removal
CVSS 6.8
CVE-2021-22784
MEDIUM
C-Bus Toolkit <1.15.8 - Auth Bypass
CVSS 5.7
CVE-2021-22772
CRITICAL
Easergy T200 Firmware < SC2-04MOD-07000100 - Unauthenticated Critical Function Access
CVSS 9.8
CVE-2021-36124
CRITICAL
Echo ShareCare <8.15.5 - Info Disclosure
CVSS 9.8
CVE-2021-28809
CRITICAL
QNAP Hybrid Backup Sync < 3.0.210507 - Improper Access Control
CVSS 9.8
CVE-2021-20474
HIGH
IBM Guardium Data Encryption <4.0.0.4 - DoS
CVSS 7.5
CVE-2021-33221
CRITICAL
CommScope Ruckus IoT Controller <1.7.1.0 - Info Disclosure
CVSS 9.8
CVE-2021-34621
CRITICAL
ProfilePress 3.0.0-3.1.3 - Unauthenticated Privilege Escalation via Registration
CVSS 9.8
CVE-2021-20107
MEDIUM
Sloan Optima EAF/EBF Firmware - Unauthenticated BLE Interface Access
CVSS 5.4
CVE-2021-35941
HIGH
Western Digital WD My Book Live - Auth Bypass
CVSS 7.5
CVE-2021-31337
CRITICAL
SINAMICS SL150, SM150, and SM150i Firmware - Unauthenticated Telnet Access
CVSS 9.8
CVE-2021-32709
MEDIUM
Shopware <6.4.1.1 - Info Disclosure
CVSS 4.9
CVE-2021-33346
CRITICAL
D-LINK DSL-2888A - Privilege Escalation
CVSS 9.8
CVE-2021-32700
CRITICAL
Ballerina <1.2.14 - Supply Chain Attack
CVSS 9.1
CVE-2021-32659
MEDIUM
Matrix-appservice-bridge <2.6.0 - Info Disclosure
CVSS 6.5
CVE-2021-32930
CRITICAL
Advantech iView < 5.7.03.6182 - Unauthenticated Arbitrary Code Execution
CVSS 9.8
Details
Vulnerabilities
2,439
Exploit Likelihood
High