CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
2,824 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 1 of 57
- CVE-2002-1810HIGHCVSS 7.5EG 7.52002-12-31
D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and read the config.img file, which contains sensitive information such as the administrative password, the WEP encryption …
- CVE-2004-0213HIGHCVSS 7.8EG 7.82004-08-06
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Ma…
- CVE-2006-0061CRITICALCVSS 9.8EG 9.82019-11-06
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.
- CVE-2006-0062CRITICALCVSS 9.8EG 9.82019-11-06
xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.
- CVE-2007-0956HIGHCVSS v2 10.0EG 10.02007-04-06
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.
- CVE-2008-6827HIGHCVSS 7.8EG 7.82009-06-08
The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a "Shatter" style attack on the "command pr…
- CVE-2009-1780HIGHCVSS v2 7.5EG 7.52009-05-22
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass paramete…
- CVE-2010-5326CRITICALCVSS 10.0EG 10.0⚠ KEV2016-05-13
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in…
- CVE-2011-10013CRITICALCVSS 10.0EG 10.02025-08-13
Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed authorization logic fails to halt execution after a failed access check, allowing unauthenticated users to reach admin…
- CVE-2011-2187HIGHCVSS 7.8EG 7.82019-11-27
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
- CVE-2011-3055MEDIUMCVSS v2 4.3EG 4.32012-03-22
The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a crafted extension.
- CVE-2011-4190MEDIUMCVSS 5.9EG 5.92018-06-08
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific …
- CVE-2011-4322HIGHCVSS 7.5EG 7.52020-01-21
websitebaker prior to and including 2.8.1 has an authentication error in backup module.
- CVE-2012-10030CRITICALCVSS 9.8EG 9.82025-08-05
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of t…
- CVE-2012-10062HIGHCVSS 8.7EG 8.72025-08-30
A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload and execute arbitrary PHP code. The WebDAV service, accessible via /webdav/, accepts HTTP P…
- CVE-2012-2736MEDIUMCVSS 4.4EG 4.42019-12-26
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
- CVE-2013-10032HIGHCVSS 8.8EG 8.82025-07-25
An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated users to upload arbitrary files without proper validation of MIME types or extensions. …
- CVE-2013-10046HIGHCVSS 8.5EG 8.52025-08-01
A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged user to execute arbitrary code with SYSTEM privileges. The flaw resides in the acs.exe component, which exposes a named …
- CVE-2013-1793HIGHCVSS 7.5EG 7.52019-12-10
openstack-utils openstack-db has insecure password creation
- CVE-2014-125113CRITICALCVSS 9.3EG 9.32025-08-05
An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the download_agent.php endpoint. An attacker can u…
- CVE-2014-125116CRITICALCVSS 9.3EG 9.32025-07-25
A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the install.php installation script. The script remains accessible after deployment and fails to sanitize input before writing t…
- CVE-2014-125118CRITICALCVSS 9.4EG 9.42025-07-25
A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' parameter when processing login requests to login.php, allowing an authenticated attacker wit…
- CVE-2014-125124CRITICALCVSS 10.0EG 10.02025-07-31
An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input v…
- CVE-2014-125126CRITICALCVSS 9.2EG 9.22025-07-31
An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentication by sending a specific cookie header (access=3) with HTTP requests. The application�…
- CVE-2014-2590MEDIUMCVSS v2 5.0EG 5.02014-04-01
The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.
- CVE-2014-3449CRITICALCVSS 9.8EG 9.82020-01-09
BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability
- CVE-2014-4872HIGHCVSS v2 7.5EG 7.52014-10-10
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting re…
- CVE-2014-7271HIGHCVSS 7.8EG 7.82018-03-08
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.
- CVE-2014-9195HIGHCVSS v2 7.5EG 7.52015-01-17
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.
- CVE-2014-9197HIGHCVSS v2 7.8EG 7.82015-01-27
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration informatio…
- CVE-2015-10141CRITICALCVSS 9.3EG 9.32025-07-23
An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick Rethans. When remote debugging is enabled, Xdebug listens on port 9000 and accepts debugge…
- CVE-2015-2888CRITICALCVSS 9.8EG 9.82017-04-10
Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to bypass authentication, related to the MySnapCam web service.
- CVE-2015-5201HIGHCVSS 7.5EG 7.52020-02-25
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disabl…
- CVE-2015-7559LOWCVSS 2.7EG 2.72019-08-01
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected clie…
- CVE-2015-9030HIGHCVSS 7.8EG 7.82017-06-13
In all Android releases from CAF using the Linux kernel, the Hypervisor API could be misused to bypass authentication.
- CVE-2016-10364MEDIUMCVSS 6.5EG 6.52017-06-16
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissio…
- CVE-2016-15045HIGHCVSS 8.5EG 8.52025-07-23
A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepin Technology Co., Ltd.). In versions 0.9.53-1 (Deepin 15.5) and 0.9.66-1 (Deepin 15.7), th…
- CVE-2016-15046HIGHCVSS 8.6EG 8.62025-07-25
A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restrictions on the PUT method exposed by the bundled Apache ActiveMQ instance (running on port …
- CVE-2016-2004CRITICALCVSS 9.8EG 9.82016-04-21
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists because of an incomplete …
- CVE-2016-5053CRITICALCVSS 9.8EG 9.82017-04-10
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port 4000.
- CVE-2016-6540MEDIUMCVSS 6.5EG 6.52018-07-06
Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data for any Trackr device by using the tracker ID number which can be discovered as described in CVE-2016-6539. Updated ap…
- CVE-2016-6541HIGHCVSS 8.8EG 8.82018-07-06
TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to …
- CVE-2016-6544HIGHCVSS 7.5EG 7.52018-07-13
getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be exploited to alter the GPS data of a lost device.
- CVE-2016-6549MEDIUMCVSS 4.3EG 4.32018-07-13
The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications to write data to the device name attribute.
- CVE-2016-7830HIGHCVSS 8.8EG 8.82017-06-09
Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices with firmware version prior to Ver.1.22 allow an attacker on the same network segment to bypass aut…
- CVE-2016-8355CRITICALCVSS 9.9EG 9.92017-02-13
An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. CADD-Solis Medication Safety Software grants an authenticated user elevated privileges on the SQL database, which would allow …
- CVE-2016-9369CRITICALCVSS 9.8EG 9.82017-02-13
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPo…
- CVE-2016-9496MEDIUMCVSS 6.5EG 6.52018-07-13
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication. An unauthenticated user may send an HTTP GET request to http://[ip]/com/gatewayreset or http://[ip]/cgi/reboot.bin to cause the mod…
- CVE-2017-0919HIGHCVSS 7.5EG 7.52018-07-03
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they…
- CVE-2017-10271CRITICALCVSS 7.5EG 9.0⚠ KEV2017-10-19
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability al…
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →