CWE-306— Missing Authentication for Critical Function
2,158 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 24 of 44
- CVE-2023-41186MEDIUMCVSS 6.5EG 6.52024-05-03
D-Link DAP-1325 CGI Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to access various functionality on affected installations of D-Link DAP-1325 routers. Authentication is n…
- CVE-2023-41187HIGHCVSS 8.8EG 8.82024-05-03
D-Link DAP-1325 HNAP Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not req…
- CVE-2023-41255HIGHCVSS 8.8EG 8.82023-10-25
The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the lack of authentication of the ‘su’ binary file installed on the device that can be a…
- CVE-2023-41333MEDIUMCVSS 6.9EG 6.92023-09-27
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability to create or modify CiliumNetworkPolicy objects in a particular namespace is able to affect traffic on an entire Cilium…
- CVE-2023-41351CRITICALCVSS 9.8EG 9.82023-11-03
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for …
- CVE-2023-41367MEDIUMCVSS 5.3EG 5.32023-09-12
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerabi…
- CVE-2023-41918CRITICALCVSS 10.0EG 10.02024-07-02
A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this to unauthenticated execute commands potentially leading to unauthorized data manipulation, access to privileged functi…
- CVE-2023-42121CRITICALCVSS 9.8EG 9.82024-05-03
Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is not required to exploit th…
- CVE-2023-42770CRITICALCVSS 10.0EG 10.02023-11-21
Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message is received over TCP/IP the RTU will simply accept the mes…
- CVE-2023-42793CRITICALCVSS 9.8EG 9.8⚠ KEV2023-09-19
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
- CVE-2023-42845MEDIUMCVSS 5.3EG 5.32023-10-25
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. Photos in the Hidden Photos Album may be viewed without authentication.
- CVE-2023-43045MEDIUMCVSS 5.9EG 5.92023-10-23
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authentication. IBM X-Force ID: 266896.
- CVE-2023-43271CRITICALCVSS 9.1EG 9.12023-10-09
Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the driving recorder through ftp and other protocols.
- CVE-2023-4334HIGHCVSS 7.5EG 7.52023-08-15
Broadcom RAID Controller Web server (nginx) is serving private files without any authentication
- CVE-2023-4335HIGHCVSS 7.5EG 7.52023-08-15
Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
- CVE-2023-43644CRITICALCVSS 9.1EG 9.12023-09-25
Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able …
- CVE-2023-44116CRITICALCVSS 9.8EG 9.82023-10-11
Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized.
- CVE-2023-44152CRITICALCVSS 9.1EG 6.12023-09-27
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
- CVE-2023-44413HIGHCVSS 7.5EG 5.92024-05-03
D-Link D-View shutdown_coreserver Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of D-Link D-View. Authentication is not …
- CVE-2023-4505LOWCVSS 2.2EG 2.22023-09-27
The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it p…
- CVE-2023-4506LOWCVSS 2.2EG 2.22023-09-27
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible …
- CVE-2023-45140MEDIUMCVSS 4.8EG 4.82023-11-08
The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. SCP and SFTP plugins don't honor group-based JIT MFA. Establishing a SCP/SFTP connection through The Bastion via a group access where MFA i…
- CVE-2023-4516HIGHCVSS 7.8EG 7.82023-09-14
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an upd…
- CVE-2023-45220HIGHCVSS 8.8EG 8.82023-10-25
The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker en…
- CVE-2023-45851HIGHCVSS 8.8EG 8.82023-10-25
The Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication. This issue allows an attacker to force the Android Client application to connect to a malicio…
- CVE-2023-46096MEDIUMCVSS 6.5EG 6.52023-11-14
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly authenticate users in the PUD Manager web service. This could allow an unauthenticated adjacent attacker t…
- CVE-2023-46249CRITICALCVSS 9.6EG 9.62023-10-31
authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any aut…
- CVE-2023-46381HIGHCVSS 8.2EG 8.22023-11-04
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the preinstalled version of LWEB-802 via an lweb802_pre/ URI. An unauthenticated attacker can edit…
- CVE-2023-46747CRITICALCVSS 9.8EG 9.8⚠ KEV2023-10-26
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Softwar…
- CVE-2023-46819MEDIUMCVSS 5.3EG 5.32023-11-07
Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09. Users are recommended to upgrade to version 18.12.09
- CVE-2023-46978HIGHCVSS 7.5EG 7.52023-10-31
TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwords without authentication.
- CVE-2023-4699CRITICALCVSS 10.0EG 9.12023-11-06
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-…
- CVE-2023-4702CRITICALCVSS 9.8EG 10.02023-09-14
Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypass. This issue affects Digital Yepas: before 1.0.1.
- CVE-2023-47166HIGHCVSS 8.8EG 8.82024-05-01
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. An attacker can send a network request to trigger …
- CVE-2023-47232MEDIUMCVSS 4.3EG 4.32025-12-21
Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: from n/a through 1.2.6.
- CVE-2023-47674CRITICALCVSS 9.8EG 9.82023-11-16
Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only …
- CVE-2023-4815HIGHCVSS 8.8EG 8.82023-09-07
Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.
- CVE-2023-48426CRITICALCVSS 10.0EG 10.02024-04-05
u-boot bug that allows for u-boot shell and interrupt over UART
- CVE-2023-4857HIGHCVSS 7.5EG 7.52024-04-15
An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information.
- CVE-2023-4884MEDIUMCVSS 6.5EG 6.52023-10-03
An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.
- CVE-2023-49115HIGHCVSS 7.5EG 7.52024-02-01
MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.
- CVE-2023-49255CRITICALCVSS 9.8EG 9.82024-01-12
The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. If any other user is currently logged in, the anonymous user…
- CVE-2023-49617CRITICALCVSS 10.0EG 10.02024-02-01
The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without any authentication.
- CVE-2023-49693CRITICALCVSS 9.8EG 9.82023-11-29
NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.
- CVE-2023-50199HIGHCVSS 8.8EG 8.82024-05-03
D-Link G416 httpd Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link G416 routers. Authenticat…
- CVE-2023-50263LOWCVSS 3.7EG 3.72023-12-12
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 1.x and 2.0.x prior to 1.6.7 and 2.0.6, the URLs `/files/get…
- CVE-2023-51062MEDIUMCVSS 5.3EG 5.32024-01-13
An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command.
- CVE-2023-51478CRITICALCVSS 9.8EG 9.82024-04-25
Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.
- CVE-2023-51571HIGHCVSS 7.5EG 7.52024-04-01
Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Voltronic Power ViewPower P…
- CVE-2023-51587HIGHCVSS 7.5EG 7.52024-05-03
Voltronic Power ViewPower getModbusPassword Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Voltronic Power ViewPower. A…
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →