CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,452 vulnerabilities with CWE-306
CVE-2020-0052 MEDIUM
Android 10 - Unauthenticated SMS Sending via Lock Screen Permissions Bypass
CVSS 4.3
CVE-2020-5328 CRITICAL
Dell EMC Isilon OneFS < 8.2.0 - Unauthenticated Unauthorized Access via SyncIQ
CVSS 9.8
CVE-2020-9544 HIGH
D-Link DSL-2640B E1 EU_1.01 - Unauthenticated Firmware Update
CVSS 7.5
CVE-2020-9330 HIGH
Xerox WorkCentre Multiple Models Firmware < 073.xxx.000.02300 - LDAP Bind Credential Change Auth Bypass
CVSS 8.8
CVE-2020-5326 MEDIUM
Dell Client Platforms - BIOS Setup Authentication Bypass via iRST Manager Optimized Defaults
CVSS 6.1
CVE-2020-6186 HIGH
SAP Host Agent 7.21 - Denial of Service via Authentication Request Processing
CVSS 7.5
CVE-2020-6769 CRITICAL
Bosch Video Streaming Gateway 6.42.10-6.45.08 - Unauthenticated Arbitrary Configuration Retrieval and Modification
CVSS 10.0
CVE-2020-8636 CRITICAL
OpServices OpMon 9.3.2 - Remote Code Execution
CVSS 9.8
CVE-2020-7954 HIGH
OpServices OpMon 9.3.2 - Privilege Escalation
CVSS 7.8
CVE-2020-7953 HIGH
OpServices OpMon <9.3.2 - Info Disclosure
CVSS 7.5
CVE-2020-3142 HIGH
Cisco Webex Meetings Suite/Cisco Webex Meetings Online - Info Discl...
CVSS 7.5
CVE-2020-7964 MEDIUM
Mirumee Saleor <2.9.1 - Info Disclosure
CVSS 5.3
CVE-2020-6964 HIGH
GE Healthcare ApexPro/CARESCAPE Telemetry Server <4.2 - Unauthenticated Remote Keyboard Input
CVSS 8.6
CVE-2020-7048 CRITICAL
WP Database Reset < 3.1 - Unauthenticated Database Table Reset via admin-post.php
CVSS 9.1
CVE-2020-6170 CRITICAL
Genexis Platinum-4410 <2.1 - Auth Bypass
CVSS 9.8
CVE-2019-25738 CRITICAL
WordPress Hybrid Composer 1.4.6 Unauthenticated Settings Change
CVSS 9.8
CVE-2019-25686 HIGH
Core FTP 2.0 build 653 PBSZ Unauthenticated Denial of Service
CVSS 7.5
CVE-2019-25678 HIGH
C4G BLIS 3.4 SQL Injection via users_select.php
CVSS 8.2
CVE-2019-25632 MEDIUM
phpFileManager 1.7.8 Local File Inclusion via index.php
CVSS 6.2
CVE-2019-25568 CRITICAL
Memu Play 6.0.7 Privilege Escalation via Insecure File Permissions
CVSS 9.8
CVE-2019-25483 HIGH
Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k - Command Injection
CVSS 8.4
CVE-2019-25248 HIGH
Beward N100 M2.1.6.04C014 - Info Disclosure
CVSS 7.5
CVE-2019-25240 CRITICAL
Rifatron 5brid DVR - Unauthenticated Access
CVSS 9.8
CVE-2019-25236 CRITICAL
iSeeQ Hybrid DVR WH-H4 1.03R - Info Disclosure
CVSS 9.8
CVE-2019-25227 HIGH
Tellion HN-2204AP - Info Disclosure
Details
Vulnerabilities 2,452
Exploit Likelihood High