CWE-306— Missing Authentication for Critical Function
2,154 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 16 of 44
- CVE-2021-4468HIGHCVSS 8.7EG 0.02025-11-14
PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authentication. A remote, unauthenticated attacker can directly retrieve a compressed configuration backup file from the device. The…
- CVE-2021-4469HIGHCVSS 8.7EG 0.02025-11-14
Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint without authentication. While the primary web interface on port 80 enforces authentication, the backdoor service allo…
- CVE-2021-45232CRITICALCVSS 9.8EG 9.82021-12-27
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some A…
- CVE-2021-45420CRITICALCVSS 9.8EG 9.82022-02-14
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system withou…
- CVE-2021-45878CRITICALCVSS 9.1EG 9.12022-03-21
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the web manger pages allows any user to view and modify information.
- CVE-2021-46006MEDIUMCVSS 6.5EG 6.52022-03-30
In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.
- CVE-2021-46009CRITICALCVSS 9.8EG 9.82022-03-30
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.
- CVE-2021-46371HIGHCVSS 7.5EG 7.52022-02-14
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.
- CVE-2021-46384CRITICALCVSS 9.8EG 9.82022-03-04
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability thro…
- CVE-2021-46852HIGHCVSS 7.5EG 7.52022-11-09
The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2021-47709HIGHCVSS 8.7EG 0.02025-12-09
COMMAX Smart Home System allows an unauthenticated attacker to change configuration and cause denial-of-service through the setconf endpoint. Attackers can trigger a denial-of-service scenario by sending a malformed request to the setconf …
- CVE-2021-47710HIGHCVSS 8.7EG 0.02025-12-09
COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploiting the /overview.asp endpoint. Attackers can access sensitive information, including login …
- CVE-2021-47727MEDIUMCVSS 5.3EG 5.32025-12-09
Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live video streams without authentication. Attackers can directly connect to RTP/RTSP or M-JPEG streams by requesting specific …
- CVE-2021-47731CRITICALCVSS 9.8EG 9.82025-12-09
Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocumented page. Attackers can exploit the hidden endpoint by using the hard-coded password 'S…
- CVE-2021-47802HIGHCVSS 7.5EG 7.52026-01-21
Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers to retrieve router configuration files. Attackers can send a request to /goform/getimage endpoint to download configur…
- CVE-2021-47891CRITICALCVSS 9.8EG 9.82026-01-23
Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary commands. Attackers can exploit the service by connecting to port 9512 and sending speciall…
- CVE-2021-47933CRITICALCVSS 9.8EG 9.82026-05-10
WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary nam…
- CVE-2021-47936CRITICALCVSS 9.8EG 9.82026-05-10
OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload PHP payloads through t…
- CVE-2021-47940CRITICALCVSS 9.8EG 9.82026-05-10
WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action. Attackers can send POST…
- CVE-2022-0140MEDIUMCVSS 5.3EG 5.32022-04-12
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the form entries or export it as a CSV File using the vfb-export endpoint.
- CVE-2022-0188MEDIUMCVSS 5.3EG 5.32022-02-14
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
- CVE-2022-0424MEDIUMCVSS 5.3EG 5.32022-05-09
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users
- CVE-2022-0878MEDIUMCVSS 4.6EG 6.52022-04-12
Electric Vehicle (EV) commonly utilises the Combined Charging System (CCS) for DC rapid charging. To exchange important messages such as the State of Charge (SoC) with the Electric Vehicle Supply Equipment (EVSE) CCS uses a high-bandwidth …
- CVE-2022-0922MEDIUMCVSS 6.5EG 6.52022-04-01
The software does not perform any authentication for critical system functionality.
- CVE-2022-0992CRITICALCVSS 9.8EG 9.82022-04-19
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated …
- CVE-2022-0993HIGHCVSS 8.1EG 9.82022-04-19
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs u…
- CVE-2022-1070HIGHCVSS 8.2EG 8.12022-10-21
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
- CVE-2022-1248HIGHCVSS 7.3EG 7.32022-04-06
A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/controllers/add_admin.php. An unauthenticated attacker is able to create a new admin accou…
- CVE-2022-1300CRITICALCVSS 9.8EG 9.82022-05-02
Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unauthorized access to change of data or disruption of the whole service.
- CVE-2022-1368CRITICALCVSS 9.8EG 9.82022-09-06
The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Authentication for Critical Function, which allows unauthorized users to change the operator account password via webserve…
- CVE-2022-1388CRITICALCVSS 9.8EG 9.8⚠ KEV2022-05-05
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authen…
- CVE-2022-1521CRITICALCVSS 9.1EG 9.12022-06-24
LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.
- CVE-2022-1598MEDIUMCVSS 5.3EG 5.32022-06-08
The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.
- CVE-2022-20060MEDIUMCVSS 6.6EG 6.62022-03-10
In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution p…
- CVE-2022-20830MEDIUMCVSS 5.3EG 5.32022-10-10
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC without authentication. Th…
- CVE-2022-20857CRITICALCVSS 9.8EG 9.82022-07-21
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information abo…
- CVE-2022-20858CRITICALCVSS 9.8EG 9.82022-07-21
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information abo…
- CVE-2022-20861CRITICALCVSS 9.8EG 8.82022-07-21
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information abo…
- CVE-2022-2138HIGHCVSS 8.2EG 7.52022-07-22
The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of-service condition.
- CVE-2022-2141CRITICALCVSS 9.8EG 9.82022-07-20
SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.
- CVE-2022-21587CRITICALCVSS 9.8EG 9.8⚠ KEV2022-10-18
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attack…
- CVE-2022-21691MEDIUMCVSS 4.3EG 4.32022-01-18
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions chat participants can spoof their channel leave message, tricking others…
- CVE-2022-21816MEDIUMCVSS 5.5EG 5.52022-02-07
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on the hypervisor host, leading to a denial of service.
- CVE-2022-21952HIGHCVSS 7.5EG 7.52022-06-22
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE …
- CVE-2022-22309MEDIUMCVSS 6.8EG 6.82022-05-24
The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability can be more critical if the serial port is connected to a serial-over-lan device. IBM X-Force ID: 217095.
- CVE-2022-2242CRITICALCVSS 9.8EG 9.82022-08-10
The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when access control is not available or not enabled (default).
- CVE-2022-22526CRITICALCVSS 9.8EG 9.82022-09-28
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API.
- CVE-2022-22576HIGHCVSS 8.1EG 8.12022-05-26
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as…
- CVE-2022-22652MEDIUMCVSS 6.1EG 6.12022-03-18
The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock to interact with the GSMA authentication panel. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical …
- CVE-2022-22809MEDIUMCVSS 5.3EG 5.32022-02-09
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations. Affected Produc…
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →