CWE-306— Missing Authentication for Critical Function
2,152 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 1 of 44
- CVE-2002-1810HIGHCVSS 7.5EG 7.52002-12-31
D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and read the config.img file, which contains sensitive information such as the administrative password, the WEP encryption …
- CVE-2004-0213HIGHCVSS 7.8EG 7.82004-08-06
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Ma…
- CVE-2006-0061CRITICALCVSS 9.8EG 9.82019-11-06
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.
- CVE-2006-0062CRITICALCVSS 9.8EG 9.82019-11-06
xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.
- CVE-2007-0956NONECVSS 0.0EG 0.02007-04-06
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.
- CVE-2008-6827HIGHCVSS 7.8EG 7.82009-06-08
The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a "Shatter" style attack on the "command pr…
- CVE-2009-1780NONECVSS 0.0EG 0.02009-05-22
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass paramete…
- CVE-2010-5326CRITICALCVSS 10.0EG 10.0⚠ KEV2016-05-13
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in…
- CVE-2011-10013CRITICALCVSS 10.0EG 0.02025-08-13
Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed authorization logic fails to halt execution after a failed access check, allowing unauthenticated users to reach admin…
- CVE-2011-2187HIGHCVSS 7.8EG 7.82019-11-27
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
- CVE-2011-3055NONECVSS 0.0EG 0.02012-03-22
The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a crafted extension.
- CVE-2011-4190MEDIUMCVSS 5.9EG 5.32018-06-08
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific …
- CVE-2011-4322HIGHCVSS 7.5EG 7.52020-01-21
websitebaker prior to and including 2.8.1 has an authentication error in backup module.
- CVE-2012-10030CRITICALCVSS 9.8EG 9.82025-08-05
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of t…
- CVE-2012-10062HIGHCVSS 8.7EG 0.02025-08-30
A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload and execute arbitrary PHP code. The WebDAV service, accessible via /webdav/, accepts HTTP P…
- CVE-2012-2736MEDIUMCVSS 4.4EG 4.42019-12-26
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
- CVE-2013-10032HIGHCVSS 8.8EG 8.82025-07-25
An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated users to upload arbitrary files without proper validation of MIME types or extensions. …
- CVE-2013-10046HIGHCVSS 8.5EG 0.02025-08-01
A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged user to execute arbitrary code with SYSTEM privileges. The flaw resides in the acs.exe component, which exposes a named …
- CVE-2013-1793HIGHCVSS 7.5EG 7.52019-12-10
openstack-utils openstack-db has insecure password creation
- CVE-2014-125113CRITICALCVSS 9.3EG 0.02025-08-05
An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the download_agent.php endpoint. An attacker can u…
- CVE-2014-125116CRITICALCVSS 9.3EG 0.02025-07-25
A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the install.php installation script. The script remains accessible after deployment and fails to sanitize input before writing t…
- CVE-2014-125118CRITICALCVSS 9.4EG 0.02025-07-25
A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' parameter when processing login requests to login.php, allowing an authenticated attacker wit…
- CVE-2014-125124CRITICALCVSS 10.0EG 0.02025-07-31
An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input v…
- CVE-2014-125126CRITICALCVSS 9.2EG 0.02025-07-31
An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentication by sending a specific cookie header (access=3) with HTTP requests. The application�…
- CVE-2014-2590NONECVSS 0.0EG 0.02014-04-01
The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.
- CVE-2014-3449CRITICALCVSS 9.8EG 9.82020-01-09
BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability
- CVE-2014-4872NONECVSS 0.0EG 0.02014-10-10
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting re…
- CVE-2014-7271HIGHCVSS 7.8EG 7.82018-03-08
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.
- CVE-2014-9195NONECVSS 0.0EG 0.02015-01-17
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.
- CVE-2014-9197NONECVSS 0.0EG 0.02015-01-27
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration informatio…
- CVE-2015-10141CRITICALCVSS 9.3EG 0.02025-07-23
An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick Rethans. When remote debugging is enabled, Xdebug listens on port 9000 and accepts debugge…
- CVE-2015-5201HIGHCVSS 7.5EG 7.52020-02-25
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disabl…
- CVE-2015-7559LOWCVSS 2.7EG 2.72019-08-01
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected clie…
- CVE-2016-15045HIGHCVSS 8.5EG 0.02025-07-23
A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepin Technology Co., Ltd.). In versions 0.9.53-1 (Deepin 15.5) and 0.9.66-1 (Deepin 15.7), th…
- CVE-2016-15046HIGHCVSS 8.6EG 0.02025-07-25
A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restrictions on the PUT method exposed by the bundled Apache ActiveMQ instance (running on port …
- CVE-2016-6540MEDIUMCVSS 6.5EG 6.52018-07-06
Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data for any Trackr device by using the tracker ID number which can be discovered as described in CVE-2016-6539. Updated ap…
- CVE-2016-6541HIGHCVSS 8.8EG 8.82018-07-06
TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to …
- CVE-2016-6544HIGHCVSS 7.5EG 7.52018-07-13
getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be exploited to alter the GPS data of a lost device.
- CVE-2016-6549MEDIUMCVSS 4.3EG 4.32018-07-13
The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications to write data to the device name attribute.
- CVE-2016-9369CRITICALCVSS 9.8EG 9.82017-02-13
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPo…
- CVE-2016-9496MEDIUMCVSS 6.5EG 6.52018-07-13
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication. An unauthenticated user may send an HTTP GET request to http://[ip]/com/gatewayreset or http://[ip]/cgi/reboot.bin to cause the mod…
- CVE-2017-0919HIGHCVSS 7.5EG 7.52018-07-03
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they…
- CVE-2017-10271HIGHCVSS 7.5EG 9.0⚠ KEV2017-10-19
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability al…
- CVE-2017-10854HIGHCVSS 8.8EG 8.82018-03-09
Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors.
- CVE-2017-12575HIGHCVSS 7.5EG 7.52018-08-24
An issue was discovered on the NEC Aterm WG2600HP2 1.0.2. The router has a set of web service APIs for access to and setup of the configuration. Some APIs don't require authentication. An attacker could exploit this vulnerability by sendin…
- CVE-2017-12720HIGHCVSS 8.1EG 8.12018-02-15
An Improper Access Control issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The FTP server on the pump does not require authentication if the pump is configured to allow FTP c…
- CVE-2017-15123MEDIUMCVSS 5.3EG 5.32019-06-12
A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudFor…
- CVE-2017-20213HIGHCVSS 7.5EG 7.52026-01-08
FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows remote attackers to access live camera streams without credentials. Attackers can exploit the vulnerability to view unauth…
- CVE-2017-2637CRITICALCVSS 9.9EG 10.02018-07-26
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no-authentication or …
- CVE-2017-2638MEDIUMCVSS 6.5EG 6.52018-07-16
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →