CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,439 vulnerabilities with CWE-306
CVE-2021-23847 CRITICAL
Bosch CPP6, CPP7, CPP7.3 <7.80 B128 - Unauthenticated Info Exposure & Settings Modification
CVSS 9.8
CVE-2021-26928 MEDIUM
BIRD < 2.0.7 - Missing Authentication for BGP Peers
CVSS 6.8
CVE-2021-22322 HIGH
Huawei EMUI and Magic UI - Missing Authentication for Critical Function
CVSS 7.5
CVE-2021-22316 MEDIUM
Huawei EMUI and Magic UI - Missing Authentication for Critical Function
CVSS 6.8
CVE-2021-21986 CRITICAL
VMware vCenter Server - Unauthenticated Access via vSphere Plugin Authentication Bypass
CVSS 9.8
CVE-2021-30190 CRITICAL
CODESYS V2 Web-Server <1.1.9.20 - Info Disclosure
CVSS 9.8
CVE-2021-32453 MEDIUM
SITEL CAP/PRX Firmware 5.2.01 - Unauthenticated Information Exposure via HTTP
CVSS 6.5
CVE-2021-20998 CRITICAL
WAGO Managed Switches - Privilege Escalation
CVSS 10.0
CVE-2021-27571 MEDIUM
Emote Remote Mouse <4.0.0.0 - Info Disclosure
CVSS 5.3
CVE-2021-27570 MEDIUM
Emote Remote Mouse < 3.015 - Unauthenticated Arbitrary Process Termination via Crafted Packet
CVSS 5.3
CVE-2021-27569 MEDIUM
Emote Remote Mouse <4.0.0.0 - Info Disclosure
CVSS 5.3
CVE-2021-29203 CRITICAL
HPE Edgeline Infrastructure Manager < 1.22 - Unauthenticated Remote Command Execution
CVSS 9.8
CVE-2021-31793 HIGH
NightOwl WDB-20-V2 WDB-20-V2_20190314 - Unauthenticated Snapshot Access via /snapshot URI
CVSS 7.5
CVE-2021-1499 MEDIUM
Cisco HyperFlex HX Data Platform unauthenticated file upload to RCE (CVE-2021-1499)
CVSS 5.3
CVE-2021-21535 HIGH
Dell Hybrid Client < 1.5 - Unauthenticated Privilege Escalation
CVSS 7.4
CVE-2021-30167 CRITICAL
Network Camera Device - Privilege Escalation
CVSS 9.8
CVE-2021-29442 HIGH
Nacos < 1.4.1 - Unauthenticated Database Manipulation via Derby Endpoint
CVSS 8.6
CVE-2021-20697 CRITICAL
DAP-1880AC <1.21 - Privilege Escalation
CVSS 9.8
CVE-2021-20990 HIGH
Fibaro Home Center 2 and Lite Firmware < 4.600 - Unauthenticated Denial of Service via Internal Management Service
CVSS 7.5
CVE-2021-24219 MEDIUM
Thrivethemes Focusblog < 2.0.0 - Improper Access Control
CVSS 5.3
CVE-2021-30462 HIGH
VestaCP <0.9.8-24 - Privilege Escalation
CVSS 7.2
CVE-2021-28124 MEDIUM
Cohesity DataPlatform <6.3.1g, <6.4.1c, <=6.5.1b - SSRF
CVSS 5.9
CVE-2021-22997 HIGH
F5 BIG-IQ Centralized Management 6.0.0-7.x - Unauthenticated ElasticSearch Transport Service Access
CVSS 7.5
CVE-2021-22995 HIGH
F5 BIG-IQ Centralized Management 6.0.0-6.1.0 - Unauthenticated High Availability Failover via Corosync Daemon
CVSS 7.5
CVE-2021-28148 HIGH
Grafana Enterprise <6.7.6-7.4.5 - DoS
CVSS 7.5
Details
Vulnerabilities 2,439
Exploit Likelihood High