VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 109 of 169
  • CVE-2026-20803HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.01

    Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-3646HigJan 4, 2026
    risk 0.47cvss 7.3epss 0.00

    Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared owners to any device by exploiting missing permission checks. Attackers can send requests to the device share API to gain…

  • CVE-2025-20085HigDec 1, 2025
    risk 0.47cvss 7.2epss 0.00

    A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the…

  • CVE-2024-49572HigDec 1, 2025
    risk 0.47cvss 7.2epss 0.00

    A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the device. An…

  • CVE-2022-50595HigNov 6, 2025
    risk 0.47cvss 7.2epss 0.01

    Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_search_value’ parameter to the…

  • CVE-2022-50592HigNov 6, 2025
    risk 0.47cvss 7.2epss 0.01

    Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘getInventoryReportData’ parameter to the…

  • CVE-2025-11661HigOct 13, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown part. Performing manipulation results in missing authentication. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2023-6215HigOct 7, 2025
    risk 0.47cvss —epss 0.00

    A potential security vulnerability has been identified in HP Sure Start’s protection of the Intel Flash Descriptor in certain HP PC products, which might allow security bypass, arbitrary code execution, loss of integrity or confidentiality, or denial of service. HP is…

  • CVE-2025-7405HigSep 1, 2025
    risk 0.47cvss 7.3epss 0.00

    Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to read or write the device values of the product and stop the operation of the programs, since MODBUS/TCP in the…

  • CVE-2025-55581HigAug 22, 2025
    risk 0.47cvss 7.3epss 0.00

    D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. The script monitors and respawns the `dcp` and `signalc` binaries without validating their integrity, origin, or permissions. An attacker…

  • CVE-2025-54478HigAug 11, 2025
    risk 0.47cvss 7.2epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.

  • CVE-2025-44004HigAug 11, 2025
    risk 0.47cvss 7.2epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint.

  • CVE-2025-7115HigJul 7, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as critical. Affected by this issue is the function PUT of the file apps/rowboat/app/api/uploads/[fileId]/route.ts of the component Session Handler. The…

  • CVE-2025-7114HigJul 7, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulnerability is the function POST of the file apps/sim/app/api/files/upload/route.ts of the component Session Handler. The…

  • CVE-2025-5906HigJun 10, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2025-20210HigMay 7, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication in an API endpoint.…

  • CVE-2025-4019HigApr 28, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the function genCode of the file novel-admin/src/main/java/com/java2nb/common/controller/GeneratorController.java. The manipulation…

  • CVE-2024-41791HigApr 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not authenticate report creation requests. This could allow an unauthenticated remote attacker to read or clear the log files on the device, reset…

  • CVE-2024-45356HigMar 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by attackers to Access sensitive methods.

  • CVE-2024-31525HigMar 5, 2025
    risk 0.47cvss 7.2epss 0.00

    Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin and gain complete access to the system as the authorization mechanism is not validated on the server side and only on the client…