VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 125 of 149
  • CVE-2020-25048MedAug 31, 2020
    risk 0.30cvss 4.6epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Quick Share feature allows unauthenticated downloads, aka file injection. The Samsung ID is SVE-2020-17760 (August 2020).

  • CVE-2019-5451MedJul 30, 2019
    risk 0.30cvss 4.6epss 0.00

    Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.

  • CVE-2017-2708MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by special steps. Due to missing authentication of the 'Find Phone'…

  • CVE-2026-7113MedApr 27, 2026
    risk 0.29cvss 5.6epss 0.00

    A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication.…

  • CVE-2026-3194MedFeb 25, 2026
    risk 0.29cvss 4.5epss 0.00

    A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Master Passphrase Handler. This manipulation causes missing authentication. The attack can only be executed locally. The attack's…

  • CVE-2025-47272MedJun 2, 2025
    risk 0.29cvss 5.5epss 0.00

    The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to delete their accounts without requiring password re-authentication. An attacker with temporary access to an authenticated session (e.g., on a shared/public…

  • CVE-2012-2736MedDec 26, 2019
    risk 0.29cvss 4.4epss 0.00

    In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.

  • CVE-2026-47671MedJul 21, 2026
    risk 0.28cvss 5.4epss 0.00

    Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` exposes the Mimir GraphQL API with dummy authorization directives and permissive CORS. When a developer is running the local…

  • CVE-2026-45397MedMay 15, 2026
    risk 0.28cvss 5.3epss 0.01

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns live RAG pipeline configuration to any unauthenticated HTTP client. No Authorization header, cookie, or API key is required. Every…

  • CVE-2025-15509MedFeb 27, 2026
    risk 0.28cvss 4.3epss 0.00

    The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2023-47232MedDec 21, 2025
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: from n/a through 1.2.6.

  • CVE-2025-64056MedDec 5, 2025
    risk 0.28cvss 4.3epss 0.00

    File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.

  • CVE-2025-63435MedNov 24, 2025
    risk 0.28cvss 4.3epss 0.00

    Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any authentication. This allows an unauthenticated remote attacker to freely…

  • CVE-2025-55073MedNov 14, 2025
    risk 0.28cvss 5.4epss 0.00

    Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow which allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL.

  • CVE-2025-47850MedMay 20, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning

  • CVE-2025-1495MedMay 3, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Business Automation Workflow 24.0.0 and 24.0.1 through 24.0.1 IF001 Center may leak sensitive information due to missing authorization validation.

  • CVE-2025-32357MedApr 5, 2025
    risk 0.28cvss 4.3epss 0.00

    In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.

  • CVE-2025-0256MedMar 24, 2025
    risk 0.28cvss 4.3epss 0.00

    HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.

  • CVE-2024-8057MedMar 20, 2025
    risk 0.28cvss 4.3epss 0.00

    In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them to an existing connector. This issue arises because the system allows an unauthenticated attacker to sign up with a basic account and perform actions that…

  • CVE-2024-12869MedMar 20, 2025
    risk 0.28cvss 4.3epss 0.01

    In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite…