VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 129 of 169
  • CVE-2026-45577MedMay 29, 2026
    risk 0.38cvss —epss 0.00

    Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth…

  • CVE-2026-34289MedApr 21, 2026
    risk 0.38cvss 5.9epss 0.00

    Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise…

  • CVE-2026-34288MedApr 21, 2026
    risk 0.38cvss 5.9epss 0.00

    Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-5300MedApr 8, 2026
    risk 0.38cvss 5.9epss 0.00

    Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data via HTTP requests

  • CVE-2025-67805MedApr 1, 2026
    risk 0.38cvss 5.9epss 0.00

    A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposing sensitive information such as hashes and table names. This feature is disabled by default in all installations and never…

  • CVE-2025-42885MedNov 11, 2025
    risk 0.38cvss 5.8epss 0.00

    Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled function that will enable them to view information. As a result, it has a low impact on the confidentiality but no impact on the integrity and availability of the…

  • CVE-2025-12436MedNov 10, 2025
    risk 0.38cvss 5.9epss 0.00

    Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2025-34230MedSep 29, 2025
    risk 0.38cvss 5.8epss 0.01

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a blind server-side request forgery (SSRF) vulnerability reachable via the /var/www/app/console_release/hp/log_off_single…

  • CVE-2025-34229MedSep 29, 2025
    risk 0.38cvss 5.8epss 0.01

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a blind server-side request forgery (SSRF) vulnerability reachable via the /var/www/app/console_release/hp/installApp.…

  • CVE-2025-36756MedSep 10, 2025
    risk 0.38cvss —epss 0.00

    A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known.

  • CVE-2025-58318MedSep 1, 2025
    risk 0.38cvss —epss 0.00

    Delta Electronics DIAView has an authentication bypass vulnerability.

  • CVE-2025-4382MedMay 9, 2025
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys stored in the TPM, it reads the decryption key into system memory. If an attacker with physical access can…

  • CVE-2024-8530MedOct 11, 2024
    risk 0.38cvss 5.9epss 0.01

    CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logcaptures” archive is accessed directly by HTTPS.

  • CVE-2024-8321MedSep 10, 2024
    risk 0.38cvss 5.8epss 0.02

    Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.

  • CVE-2024-1573MedJul 4, 2024
    risk 0.38cvss 5.9epss 0.01

    Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.2 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.2 and prior, Mitsubishi Electric Hyper Historian versions 10.97.2 and prior,…

  • CVE-2023-37495MedFeb 29, 2024
    risk 0.38cvss 5.9epss 0.00

    Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the…

  • CVE-2024-21306MedJan 9, 2024
    risk 0.38cvss 5.7epss 0.06

    Microsoft Bluetooth Driver Spoofing Vulnerability

  • CVE-2023-6368MedDec 14, 2023
    risk 0.38cvss 5.9epss 0.01

    In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate information related to a registered device being monitored by WhatsUp Gold.

  • CVE-2023-27256MedOct 25, 2023
    risk 0.38cvss 5.8epss 0.01

    Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of sensitive log files by unauthenticated attackers.

  • CVE-2023-43045MedOct 23, 2023
    risk 0.38cvss 5.9epss 0.01

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authentication. IBM X-Force ID: 266896.