VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 113 of 150
  • CVE-2025-12941MedDec 9, 2025
    risk 0.37cvss 5.7epss 0.00

    Denial of Service Vulnerability in NETGEAR C6220 and C6230 (DOCSIS® 3.0 Two-in-one Cable Modem + WiFi Router) allows authenticated local WiFi users reboot the router.

  • CVE-2023-3104MedNov 22, 2023
    risk 0.37cvss 5.7epss 0.01

    Lack of authentication vulnerability. An unauthenticated local user is able to see through the cameras using the web server due to the lack of any form of authentication.

  • CVE-2023-25780MedJun 2, 2023
    risk 0.37cvss 5.7epss 0.00

    It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.

  • CVE-2020-27019MedNov 9, 2020
    risk 0.37cvss 5.5epss 0.18

    Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulnerability which could allow an attacker to access a specific database and key.

  • CVE-2026-60595MedJul 21, 2026
    risk 0.36cvss 5.5epss 0.00

    Vulnerability in the PeopleSoft Enterprise FIN Pay/Bill Management product of Oracle PeopleSoft (component: Paybill Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure…

  • CVE-2026-41047MedJun 22, 2026
    risk 0.36cvss 5.5epss 0.00

    Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information.

  • CVE-2026-9212MedJun 9, 2026
    risk 0.36cvss epss 0.00

    Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.

  • CVE-2026-9371MedMay 24, 2026
    risk 0.36cvss 5.6epss 0.00

    A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.ts of the component API. The manipulation leads to missing authentication. The attack may be initiated remotely. The attack's…

  • CVE-2026-6369MedApr 20, 2026
    risk 0.36cvss 5.5epss 0.00

    An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain…

  • CVE-2025-15515MedMar 13, 2026
    risk 0.36cvss 5.5epss 0.00

    The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local network, it can cause data leakage

  • CVE-2026-3192MedFeb 25, 2026
    risk 0.36cvss 5.6epss 0.01

    A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of the component RPC Credential Handler. The manipulation leads to improper authentication. The attack is possible to be carried out…

  • CVE-2025-48608MedDec 8, 2025
    risk 0.36cvss 5.5epss 0.00

    In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-45355MedMar 27, 2025
    risk 0.36cvss 5.5epss 0.00

    A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by attackers to Access sensitive methods.

  • CVE-2024-13772MedMar 14, 2025
    risk 0.36cvss 5.6epss 0.00

    The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax_login_or_register and…

  • CVE-2025-21559MedJan 21, 2025
    risk 0.36cvss 5.5epss 0.01

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple…

  • CVE-2023-52949MedSep 26, 2024
    risk 0.36cvss 5.5epss 0.00

    Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.

  • CVE-2022-26394MedSep 9, 2022
    risk 0.36cvss 5.5epss 0.00

    The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail.

  • CVE-2021-44261MedMar 17, 2022
    risk 0.36cvss 5.3epss 0.20

    A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version information for the device.

  • CVE-2022-21816MedFeb 7, 2022
    risk 0.36cvss 5.5epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on the hypervisor host, leading to a denial of service.

  • CVE-2020-7389MedJul 22, 2021
    risk 0.36cvss 5.5epss 0.02

    Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.