VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 128 of 149
  • CVE-2024-38143MedAug 13, 2024
    risk 0.27cvss 4.2epss 0.02

    Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability

  • CVE-2024-32765MedAug 12, 2024
    risk 0.27cvss 4.2epss 0.00

    A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors. We have already fixed the vulnerability in the following…

  • CVE-2026-54246medJul 17, 2026
    risk 0.26cvss epss

    ## Description The `routesrv` component exposes the full cluster route topology (Ingress/RouteGroup configurations, backend URLs, filter chains, OAuth/OIDC callback paths) and cache-cluster topology (Redis/Valkey shard addresses) over plain HTTP with **zero authentication**.…

  • CVE-2026-57128medJun 18, 2026
    risk 0.26cvss epss

    ## Summary The SSE (Server-Sent Events) server in `src/praisonai-agents/praisonaiagents/server/server.py` exposes a `/publish` endpoint that broadcasts arbitrary messages to all connected clients without any authentication. The `ServerConfig` dataclass (line 24) defines an…

  • CVE-2026-42095MedApr 24, 2026
    risk 0.26cvss 4.0epss 0.00

    bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.

  • CVE-2026-21767MedApr 2, 2026
    risk 0.26cvss 4.0epss 0.00

    HCL BigFix Platform is affected by insufficient authentication.  The application might allow users to access sensitive areas of the application without proper authentication.

  • CVE-2024-55538MedJan 2, 2025
    risk 0.26cvss 4.0epss 0.00

    Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build 41736, Acronis True Image OEM (macOS) before build 42571, Acronis True Image OEM…

  • CVE-2023-52947MedSep 26, 2024
    risk 0.26cvss 4.0epss 0.00

    Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecified vectors. The backup functionality will continue to operate and will not be…

  • CVE-2024-3219MedJul 29, 2024
    risk 0.26cvss epss 0.00

    The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows. This pure-Python implementation uses AF_INET or AF_INET6 to create a local connected pair of sockets. The connection …

  • CVE-2019-1876MedJun 20, 2019
    risk 0.26cvss 4.0epss 0.02

    A vulnerability in the HTTPS proxy feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to use the Central Manager as an HTTPS proxy. The vulnerability is due to insufficient authentication of proxy connection requests.…

  • CVE-2025-5715LowJun 6, 2025
    risk 0.25cvss 3.8epss 0.00

    A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Handler. The manipulation leads to missing critical step in authentication. It is possible to launch…

  • CVE-2026-32896MedMar 21, 2026
    risk 0.24cvss 4.8epss 0.00

    The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can bypass webhook authentication by…

  • CVE-2024-54155LowDec 4, 2024
    risk 0.24cvss 3.7epss 0.00

    In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication

  • CVE-2024-39300LowAug 30, 2024
    risk 0.24cvss 3.7epss 0.00

    Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function of the product is enabled, a remote attacker may login to the product without authentication and alter the product's settings.

  • CVE-2023-36926LowAug 8, 2023
    risk 0.24cvss 3.7epss 0.00

    Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn call read functions. This allows the attacker to gather some non-sensitive information about the…

  • CVE-2022-45433LowDec 27, 2022
    risk 0.24cvss 3.7epss 0.01

    Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could get the traceroute results.

  • CVE-2021-20238LowApr 1, 2022
    risk 0.24cvss 3.7epss 0.01

    It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition configuration used for bootstrapping Nodes and can include…

  • CVE-2025-32433CriKEVApr 16, 2025
    risk 0.23cvss 10.0epss 0.99

    Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling,…

  • CVE-2024-31684LowJun 3, 2024
    risk 0.23cvss 3.5epss 0.00

    Incorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows attackers to bypass fingerprint authentication due to the use of a deprecated API.

  • CVE-2023-40170MedAug 28, 2023
    risk 0.23cvss 4.6epss 0.01

    jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via "Open image in new tab". This issue has been addressed in…