VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 120 of 149
  • CVE-2026-1332MedJan 22, 2026
    risk 0.34cvss 5.3epss 0.00

    MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meeting-related information.

  • CVE-2026-0942MedJan 16, 2026
    risk 0.34cvss 5.3epss 0.00

    The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clearOrderLogs() function in all versions up to, and including, 5.1.5. This makes it possible…

  • CVE-2024-58336MedDec 30, 2025
    risk 0.34cvss 5.3epss 0.00

    Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpoint on port 8080. Attackers can retrieve video stream data without authentication by directly accessing the specified…

  • CVE-2025-63390MedDec 18, 2025
    risk 0.34cvss 5.3epss 0.01

    An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote attackers to enumerate and retrieve detailed information about all configured…

  • CVE-2023-53773MedDec 9, 2025
    risk 0.34cvss 5.3epss 0.01

    MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attackers to generate live stream snapshots through the Simple VDR Protocol. Attackers can request /tpl/tv_action.sh to create and retrieve a live TV screenshot stored in…

  • CVE-2021-47727MedDec 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live video streams without authentication. Attackers can directly connect to RTP/RTSP or M-JPEG streams by requesting specific endpoints like p1.mjpg or p1.264 to view…

  • CVE-2025-11771MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the 'createSaleRecord' function in all versions up…

  • CVE-2025-12349MedNov 19, 2025
    risk 0.34cvss 5.3epss 0.00

    The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Authorization in versions up to, and including, 5.9.10. This is due to the plugin not properly verifying that a user is authorized to perform an action in the…

  • CVE-2023-7328MedNov 14, 2025
    risk 0.34cvss 5.3epss 0.00

    Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to retrieve structured user data, including account names and connection metadata such as client IP and timeout values.

  • CVE-2025-11986MedNov 11, 2025
    risk 0.34cvss 5.3epss 0.00

    The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_process) that allows calling the register and savenft…

  • CVE-2025-11852MedOct 16, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/device_service of the component ONVIF Service. Performing manipulation results in missing authentication. The attack is possible to be carried out remotely.…

  • CVE-2025-0275MedOct 16, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

  • CVE-2025-0274MedOct 16, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

  • CVE-2025-11728MedOct 15, 2025
    risk 0.34cvss 5.3epss 0.00

    The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the 'return_payment' and 'notice_payment' functions in all versions up to, and including, 6.0.…

  • CVE-2025-11672MedOct 13, 2025
    risk 0.34cvss 5.3epss 0.00

    Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain user group names.

  • CVE-2025-11671MedOct 13, 2025
    risk 0.34cvss 5.3epss 0.00

    Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain information such as account names and IP addresses.

  • CVE-2025-11171MedOct 8, 2025
    risk 0.34cvss 5.3epss 0.00

    The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and including, 3.5.9. This is due to the plugin registering an unauthenticated AJAX action that dispatches to admin-class methods based on a…

  • CVE-2025-34232MedSep 29, 2025
    risk 0.34cvss 5.3epss 0.01

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a blind server-side request forgery (SSRF) vulnerability reachable via the /var/www/app/console_release/lexmark/dellCheck…

  • CVE-2025-41716MedSep 24, 2025
    risk 0.34cvss 5.3epss 0.00

    The web application allows an unauthenticated remote attacker to learn information about existing user accounts with their corresponding role due to missing authentication for critical function.

  • CVE-2025-10267MedSep 12, 2025
    risk 0.34cvss 5.3epss 0.00

    NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly upload files. If the attacker manages to bypass the file extension restrictions, they could upload a webshell and execute it on the server…