CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,439 vulnerabilities with CWE-306
CVE-2021-28122 CRITICAL
Open5GS 2.1.3-2.2.0 - Unauthenticated Database Manipulation via WebUI API
CVSS 9.8
CVE-2021-20262 MEDIUM
Keycloak 12.0.0 - Missing Authentication for Critical Function
CVSS 6.8
CVE-2021-27255 HIGH
NETGEAR Multiple Router and Extender Firmware - Unauthenticated Remote Code Execution via refresh_status.aspx
CVSS 8.8
CVE-2021-26705 CRITICAL
SquareBox CatDV < 9.2 - Unauthenticated Sensitive RMI Method Invocation
CVSS 9.1
CVE-2021-27963 HIGH
SonLogger < 6.4.1 - Unauthenticated User Creation with Arbitrary Permissions via /User/saveUser
CVSS 8.2
CVE-2021-27215 CRITICAL
genua genugate < 9.0 Z p19, 9.1.x-9.6.x < 9.6 p7, 10.x < 10.1 p4 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2021-1396 CRITICAL
Cisco Application Services Engine 1.1-1.1(3e) - Unauthenticated Privileged Access
CVSS 9.8
CVE-2021-1393 CRITICAL
Cisco Application Services Engine 1.1-1.1(3e) - Unauthenticated Privileged Access
CVSS 9.8
CVE-2021-20662 HIGH
SolarView Compact SV-CPT-MC310 <6.5 - Privilege Escalation
CVSS 7.5
CVE-2021-20198 HIGH
OpenShift Installer < 0.9.0 Unauthenticated RCE via Kubelet Port
CVSS 8.1
CVE-2021-26697 MEDIUM
Apache Airflow 2.0.0 - Unauthenticated Improper Privilege Management via Experimental API Lineage Endpoint
CVSS 5.3
CVE-2021-20067 MEDIUM
Racom MIDGE Firmware 4.4.40.105 - Unauthenticated Sensitive Information Exposure via Syslog
CVSS 5.3
CVE-2021-22652 CRITICAL
Advantech iView <5.7.03.6112 - Code Execution
CVSS 9.8
CVE-2021-21472 HIGH
SAP Software Provisioning Manager 1.0 - Authenticated Security Bypass via Missing Password Configuration
CVSS 8.8
CVE-2021-25312 HIGH
HTCondor <8.9.11 - Privilege Escalation
CVSS 8.8
CVE-2021-22159 HIGH
Proofpoint Insider Threat Management < 7.4.3 - Authenticated Local Privilege Escalation via Missing Authentication
CVSS 7.8
CVE-2021-22850 MEDIUM
HGiga oaklouds_portal - Unauthenticated Privileged Function Access
CVSS 5.3
CVE-2021-1246 MEDIUM
Cisco Finesse - Unauthenticated Access to OpenSocial Gadget Editor via Crafted URL
CVSS 6.5
CVE-2020-37157 HIGH
DBPower C300 HD Camera - Info Disclosure
CVSS 7.5
CVE-2020-37146 HIGH
ACE Security WiP-90113 HD Camera - Info Disclosure
CVSS 7.5
CVE-2020-36963 HIGH
Intelbras Router RF 301K <1.1.2 - Auth Bypass
CVSS 7.5
CVE-2020-36904 HIGH
Selea CarPlateServer 4.0.1.6 - Unauthenticated Remote Program Execution via NO_LIST_EXE_PATH Configuration
CVSS 7.5
CVE-2020-36894 HIGH
Eibiz i-Media Server Digital Signage 3.8.0 - Auth Bypass
CVSS 7.5
CVE-2020-36892 CRITICAL
Eibiz i-Media Server Digital Signage 3.8.0 - Privilege Escalation
CVSS 9.8
CVE-2020-36874 HIGH
ACE SECURITY WIP-90113 HD - Info Disclosure
Details
Vulnerabilities 2,439
Exploit Likelihood High