CWE-306
High likelihoodMissing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
2,451 vulnerabilities with CWE-306
CVE-2020-9004
HIGH
Wowza Streaming Engine < 4.8.0 - Authenticated Authorization Bypass via Administration Panel
CVSS 8.8
CVE-2020-11673
CRITICAL
Responsive Poll < 1.3.4 - Unauthenticated Poll Manipulation via wp_ajax_nopriv Callback
CVSS 9.8
CVE-2020-3952
CRITICAL
KEV
VMware vCenter Server vmdir Information Disclosure
CVSS 9.8
CVE-2020-10625
CRITICAL
Advantech WebAccess/NMS < 3.0.2 - Unauthenticated Admin Account Creation
CVSS 9.8
CVE-2020-10263
MEDIUM
XIAOMI XIAOAI Speaker Pro LX06 1.52.4 - Unauthenticated Root Shell Access via UART Interface
CVSS 6.8
CVE-2020-11599
HIGH
CIPAce 6.80-9.1 - Unauthenticated Credential Exposure via GetDistributedPOP3
CVSS 7.5
CVE-2020-11598
CRITICAL
CIPPlanner CIPAce < 9.1 - Unauthenticated Remote Code Execution via Upload.ashx
CVSS 9.8
CVE-2020-9473
MEDIUM
Siedle SG 150-0 Firmware < 1.2.4 - Unauthenticated Root Access via Passwordless FTP/SSH User
CVSS 6.6
CVE-2020-10265
CRITICAL
Universal Robots ur_software 3.0.14989-3.3.3.292 - Unauthenticated Access to DashBoard Server
CVSS 9.4
CVE-2020-10264
HIGH
Universal Robots ur_software 3.0.14989-3.3.3.292 - Unauthenticated Robot Data Exposure via RTDE Interface
CVSS 8.8
CVE-2020-11547
MEDIUM
PRTG Network Monitor < 20.1.57.1745 - Unauthenticated Information Disclosure via login.htm or index.htm
CVSS 5.3
CVE-2020-9349
HIGH
CACAGOO TV-288ZD-2MP Firmware 3.4.2.0919 - Unauthenticated RTSP Service Access
CVSS 7.5
CVE-2020-8509
HIGH
Zoho ManageEngine Desktop Central <10.0.483 - Info Disclosure
CVSS 7.5
CVE-2020-3920
HIGH
UltraLog Express Firmware - Unauthenticated Privileged Account Management via System Directory
CVSS 8.1
CVE-2020-10965
HIGH
Teradici PCoIP Management Console <20.01.0, 19.11.1 - Auth Bypass
CVSS 8.1
CVE-2020-10833
HIGH
Samsung Android Q(10.0) - Unauthenticated Lockscreen Bypass via DeX Quick Panel
CVSS 7.5
CVE-2020-10874
HIGH
Motorola FX9500 - Unauthenticated Database File Read
CVSS 7.5
CVE-2020-7479
HIGH
Schneider-electric Interactive Graphi... - Missing Authentication
CVSS 7.8
CVE-2020-8497
MEDIUM
Artica Pandora FMS <7.42 - Info Disclosure
CVSS 5.3
CVE-2020-9325
HIGH
Aquaforest TIFF Server 4.0 - Unauthenticated Arbitrary File Download via Path Traversal
CVSS 7.5
CVE-2020-8598
CRITICAL
Trend Micro Apex One, OfficeScan XG, Worry-Free Business Security 9.0-10.0 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2020-10079
MEDIUM
GitLab 7.10.0-12.8.1 - Missing Authentication for Critical Function
CVSS 5.3
CVE-2020-6207
CRITICAL
KEV
SAP Solution Manager 7.2 - Auth Bypass
CVSS 9.8
CVE-2020-6198
CRITICAL
SAP Solution Manager <720 - Unauthenticated RCE
CVSS 9.8
CVE-2020-0052
MEDIUM
Android 10 - Unauthenticated SMS Sending via Lock Screen Permissions Bypass
CVSS 4.3
Details
Vulnerabilities
2,451
Exploit Likelihood
High