VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 115 of 150
  • CVE-2025-55070MedNov 14, 2025
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events

  • CVE-2025-8558MedNov 3, 2025
    risk 0.35cvss 5.4epss 0.01

    Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the licensed limit. Successful…

  • CVE-2025-53034MedOct 21, 2025
    risk 0.35cvss 5.4epss 0.00

    Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows…

  • CVE-2025-34220MedSep 29, 2025
    risk 0.35cvss 5.3epss 0.01

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contains a /api-gateway/identity/search-groups endpoint that does not require authentication. Requests to…

  • CVE-2025-9214MedSep 11, 2025
    risk 0.35cvss 5.4epss 0.00

    A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify network settings via the CUPS service.

  • CVE-2025-6226MedJul 18, 2025
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the…

  • CVE-2025-32896MedJun 19, 2025
    risk 0.35cvss 6.5epss 0.01

    # Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access `/hazelcast/rest/maps/submit-job` to submit job. An attacker can set extra params in mysql url to perform…

  • CVE-2025-48742MedMay 27, 2025
    risk 0.35cvss 5.4epss 0.00

    The installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution.

  • CVE-2025-4268MedMay 5, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input RebootSystem leads to missing authentication. The attack…

  • CVE-2025-24271MedApr 29, 2025
    risk 0.35cvss 5.4epss 0.00

    An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An unauthenticated user on the same network as a signed-in Mac…

  • CVE-2025-4018MedApr 28, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue affects the function addCrawlSource of the file novel-crawl/src/main/java/com/java2nb/novel/controller/CrawlController.java. The…

  • CVE-2025-4015MedApr 28, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issue is the function list of the file novel-system/src/main/java/com/java2nb/system/controller/SessionController.java. The…

  • CVE-2024-39773MedJan 14, 2025
    risk 0.35cvss 5.3epss 0.01

    An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2024-33616MedNov 26, 2024
    risk 0.35cvss 5.3epss 0.01

    Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporation states the telnet feature is implemented on older models only, and is planning to provide the firmware update to remove the…

  • CVE-2024-41968MedNov 18, 2024
    risk 0.35cvss 5.4epss 0.00

    A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.

  • CVE-2024-8320MedSep 10, 2024
    risk 0.35cvss 5.3epss 0.01

    Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.

  • CVE-2023-37325MedMay 7, 2024
    risk 0.35cvss 5.4epss 0.00

    D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to make unauthorized changes to device configuration on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this…

  • CVE-2023-39466MedMay 3, 2024
    risk 0.35cvss 5.3epss 0.01

    Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not…

  • CVE-2024-2076MedMar 1, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file booking.php/owner.php/tenant.php. The manipulation leads to missing authentication. The attack may be…

  • CVE-2024-21619MedJan 25, 2024
    risk 0.35cvss 5.3epss 0.01

    A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access…