CWE-306

High likelihood

Missing Authentication for Critical Function

Parent: CWE-287 - Improper Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,453 vulnerabilities with CWE-306
CVE-2014-125124 CRITICAL
Pandora FMS <= 5.0RC1 - Unauthenticated Remote Command Execution via Anyterm p Parameter
CVE-2014-125118 CRITICAL
eScan Web Management Console <5.5-2 - Command Injection
CVE-2014-125116 CRITICAL
HybridAuth 2.0.9-2.2.2 - Unauthenticated Remote Code Execution via install.php Config Injection
CVE-2014-3449 CRITICAL
BSS Continuity CMS 4.2.22640.0 - Authentication Bypass
CVSS 9.8
CVE-2014-7271 HIGH
SDDM <0.10.0 - Privilege Escalation
CVSS 7.8
CVE-2014-9197
Schneider Electric ETG3000 - Info Disclosure
CVE-2014-9195
Phoenix Contact ProConOs & MultiProg - RCE
CVE-2014-4872
BMC Track-It! 11.3.0.355 - Unauthenticated Remote Code Execution via .NET Remoting
CVE-2014-2590
Siemens RuggedCom ROS <3.11-4.0 - DoS
CVE-2013-10046 HIGH
Agnitum Outpost Internet Security 8.1 - Privilege Escalation
CVE-2013-10032 HIGH
GetSimpleCMS <3.2.1 - Authenticated RCE
CVSS 8.8
CVE-2013-1793 HIGH
OpenStack - Missing Authentication for Critical Function in Password Creation
CVSS 7.5
CVE-2012-10062 HIGH
XAMPP < 1.7.3 - Authenticated Remote Code Execution via WebDAV PHP Upload
CVE-2012-10030 CRITICAL
FreeFloat FTP Server - Unauthenticated RCE
CVSS 9.8
CVE-2012-2736 MEDIUM
NetworkManager 0.9.2.0 - Info Disclosure
CVSS 4.4
CVE-2011-10013 CRITICAL
Traq Project Issue Tracking System 2.0-2.3 - Unauthenticated Remote Code Execution via Admin Plugin Injection
CVE-2011-4322 HIGH
WebsiteBaker <= 2.8.1 - Unauthenticated Backup Module Access
CVSS 7.5
CVE-2011-2187 HIGH
xscreensaver <5.14 - Info Disclosure
CVSS 7.8
CVE-2011-4190 MEDIUM
kdump <2012-01-20 - Info Disclosure
CVSS 5.9
CVE-2011-3055
Google Chrome < 17.0.963.83 - Unauthenticated Extension Installation
CVE-2010-5326 CRITICAL KEV
SAP NetWeaver Application Server Java <7.3 - RCE
CVSS 10.0
CVE-2009-1780
Frax.dk Php Recommend <= 1.3 - Unauthenticated Privilege Escalation via Password Change
CVE-2008-6827 HIGH
Symantec Altiris Deployment Solution 6.0-6.9.355 - Local Privilege Escalation via Shatter Attack on AClient.exe
CVSS 7.8
CVE-2007-0956
MIT Kerberos 5 < 1.6.1 - Unauthenticated Authentication Bypass via Telnet Username Prefix
CVE-2006-0062 CRITICAL
xlockmore 5.13 - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities 2,453
Exploit Likelihood High