VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 124 of 149
  • CVE-2022-26067MedMay 25, 2022
    risk 0.32cvss 4.9epss 0.01

    An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to arbitrary file read. An attacker can send a sequence of requests to…

  • CVE-2021-32709MedJun 24, 2021
    risk 0.32cvss 4.9epss 0.01

    Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users are recommend to update to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download…

  • CVE-2020-19670MedSep 30, 2020
    risk 0.32cvss 4.9epss 0.01

    In Niushop B2B2C Multi-Business Basic Edition V1.11, authentication can be bypassed, causing administrators to reset any passwords.

  • CVE-2020-13920MedSep 10, 2020
    risk 0.32cvss 5.9epss 0.05

    Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates…

  • CVE-2019-20105MedMar 17, 2020
    risk 0.32cvss 4.9epss 0.01

    The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote…

  • CVE-2026-66139MedJul 24, 2026
    risk 0.31cvss 4.8epss 0.00

    OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.

  • CVE-2026-54068MedJun 24, 2026
    risk 0.31cvss 5.9epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from authentication in SiYuan's kernel router (router.go, "不需要鉴权" -- no auth needed). When called with type=8 and a valid block…

  • CVE-2026-29613MedMar 5, 2026
    risk 0.31cvss 5.9epss 0.00

    OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests based solely on loopback remoteAddress without validating forwarding headers, allowing bypass of configured webhook passwords.…

  • CVE-2026-27482MedFeb 21, 2026
    risk 0.31cvss 5.9epss 0.00

    Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthenticated by default. If the dashboard/agent is reachable (e.g., --dashboard-host=0.0.0.0), a web page…

  • CVE-2020-12491MedNov 25, 2024
    risk 0.31cvss epss 0.00

    Improper control of framework service permissions with possibility of some sensitive device information leakage.

  • CVE-2024-30391MedApr 12, 2024
    risk 0.31cvss 4.8epss 0.00

    A Missing Authentication for Critical Function vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated network-based attacker to cause limited impact to the integrity or availability of…

  • CVE-2023-45140MedNov 8, 2023
    risk 0.31cvss 4.8epss 0.00

    The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. SCP and SFTP plugins don't honor group-based JIT MFA. Establishing a SCP/SFTP connection through The Bastion via a group access where MFA is enforced does not ask for additional…

  • CVE-2023-20003MedMay 18, 2023
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vulnerability is due to a logic error with the social login…

  • CVE-2023-31143MedMay 9, 2023
    risk 0.31cvss 5.9epss 0.01

    mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in version 0.8.34 and prior to 0.8.72 with user authentication enabled may be affected by a vulnerability. The terminal could be accessed by users who are not signed…

  • CVE-2020-11028MedApr 30, 2020
    risk 0.31cvss 5.8epss 0.02

    In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3,…

  • CVE-2024-38279MedJun 13, 2024
    risk 0.30cvss 4.6epss 0.00

    The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.

  • CVE-2024-35342MedMay 28, 2024
    risk 0.30cvss 4.6epss 0.00

    Certain Anpviz products allow unauthenticated users to modify or disable camera related settings such as microphone volume, speaker volume, LED lighting, NTP, motion detection, etc. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380,…

  • CVE-2022-3312MedNov 1, 2022
    risk 0.30cvss 4.6epss 0.00

    Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restrictions via physical access to the device. (Chromium security severity: Medium)

  • CVE-2022-0878MedApr 12, 2022
    risk 0.30cvss 4.6epss 0.00

    Electric Vehicle (EV) commonly utilises the Combined Charging System (CCS) for DC rapid charging. To exchange important messages such as the State of Charge (SoC) with the Electric Vehicle Supply Equipment (EVSE) CCS uses a high-bandwidth IP link provided by the HomePlug Green…

  • CVE-2020-27902MedDec 8, 2020
    risk 0.30cvss 4.6epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2. A person with physical access to an iOS device may be able to access stored passwords without authentication.