CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,343 vulnerabilities with CWE-306
CVE-2026-4810
CRITICAL
Remote Code Execution in Google Agent Development Kit (ADK)
CVE-2026-6129
HIGH
zhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authentication
CVSS 7.3
CVE-2026-6126
HIGH
zhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authentication
CVSS 7.3
CVE-2026-5724
MEDIUM
Missing Authentication on Streaming gRPC Replication Endpoint
CVE-2026-40184
LOW
Unauthenticated Access to Uploaded Files in TREK
CVSS 3.7
CVE-2026-5777
HIGH
Security Misconfiguration Vulnerability in Atom 3x Projector
CVE-2026-39848
MEDIUM
Dockyard's Unauthenticated Cron Endpoint in Dockyard Enables Container Enumeration and Database Manipulation
CVSS 6.5
CVE-2026-33788
HIGH
Junos OS Evolved: Local, authenticated attacker can gain privileged access to FPCs
CVSS 7.8
CVE-2026-4436
HIGH
GPL Odorizers GPL750 Missing Authentication for Critical Function
CVSS 8.6
CVE-2026-39987
CRITICAL
KEV
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
CVSS 9.8
CVE-2026-39393
HIGH
Post-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4ms
CVSS 8.1
CVE-2026-5300
MEDIUM
Missing Authentication for Critical Function in coolercontrold
CVSS 5.9
CVE-2026-39363
HIGH
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
CVSS 7.5
CVE-2026-35584
MEDIUM
FreeScout <1.8.212 Open Tracking Endpoint - Insecure Direct Object Reference
CVSS 6.5
CVE-2026-35523
HIGH
Authentication bypass in strawberry-graphql via legacy graphql-ws WebSocket subprotocol
CVSS 7.5
CVE-2026-22679
CRITICAL
Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint
CVSS 9.8
CVE-2026-1900
MEDIUM
Link Whisper Free < 0.9.1 - Unauthenticated Settings and User Meta Update
CVSS 6.5
CVE-2026-35450
MEDIUM
WWBN AVideo has Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php
CVSS 5.3
CVE-2026-5676
HIGH
Totolink A8000R cstecgi.cgi setLanguageCfg missing authentication
CVSS 7.3
CVE-2026-26027
HIGH
GLPI 11.0.0-11.0.5 Inventory - Unauthenticated Stored Cross-Site Scripting
CVSS 7.5
CVE-2026-5632
HIGH
assafelovic gpt-researcher HTTP REST API Endpoint missing authentication
CVSS 7.3
CVE-2026-5616
HIGH
JeecgBoot AI Chat JeecgBizToolsProvider.java missing authentication
CVSS 7.3
CVE-2026-4272
HIGH
Honeywell Barcode Scanners - Auth Bypass
CVSS 8.1
CVE-2026-34952
CRITICAL
PraisonAI: Missing Authentication in WebSocket Gateway
CVSS 9.1
CVE-2026-32646
HIGH
Gardyn Cloud API Missing Authentication for Critical Function
CVSS 7.5
Details
Vulnerabilities
2,343
Exploit Likelihood
High