VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 129 of 149
  • CVE-2020-13838LowJun 4, 2020
    risk 0.23cvss 3.5epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscreen feature does not block access to Quick Panel and notifications. The Samsung ID is SVE-2020-17187 (June 2020).

  • CVE-2020-13837LowJun 4, 2020
    risk 0.23cvss 3.5epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) software. The Lockscreen feature does not block Quick Panel access to Music Share. The Samsung ID is SVE-2020-17145 (June 2020).

  • CVE-2019-19092LowApr 2, 2020
    risk 0.23cvss 3.5epss 0.01

    ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstate might thus not be noticed.

  • CVE-2026-54776MedJul 8, 2026
    risk 0.22cvss 4.4epss 0.00

    CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service hosted on Unix Domain Sockets with PosixIdentity client credentials can accept connections that skip the application/unixposix stream upgrade…

  • CVE-2025-15567LowFeb 27, 2026
    risk 0.21cvss 3.3epss 0.00

    Insufficient protection mechanisms in the Health Module may lead to partial information disclosure.

  • CVE-2025-14058LowJan 14, 2026
    risk 0.21cvss 3.2epss 0.00

    A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.

  • CVE-2025-47870MedAug 21, 2025
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the team’s invite id.

  • CVE-2024-6582MedSep 13, 2024
    risk 0.21cvss 4.3epss 0.00

    A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to…

  • CVE-2023-0463LowJan 26, 2023
    risk 0.21cvss 3.3epss 0.00

    The force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022.3.30 allows a user to save sensitive data on disk.

  • CVE-2022-4018MedNov 16, 2022
    risk 0.21cvss 4.3epss 0.01

    Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

  • CVE-2026-47122MedJul 21, 2026
    risk 0.20cvss 4.2epss 0.00

    Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. After `_performedStage1Installation = YES`, new…

  • CVE-2024-54153LowDec 4, 2024
    risk 0.20cvss 3.1epss 0.00

    In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

  • CVE-2024-53701LowNov 29, 2024
    risk 0.20cvss 3.1epss 0.00

    Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications can be set not to be displayed, etc. Under certain conditions, and when an attacker can directly operate the device which its screen is unlocked by a user,…

  • CVE-2020-26173LowDec 18, 2020
    risk 0.20cvss 3.1epss 0.01

    An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required.

  • CVE-2025-31963LowJan 7, 2026
    risk 0.19cvss 2.9epss 0.00

    Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.

  • CVE-2026-47038LowJul 21, 2026
    risk 0.18cvss 2.7epss 0.00

    Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to…

  • CVE-2026-40184LowApr 10, 2026
    risk 0.17cvss 3.7epss 0.00

    TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. This vulnerability is fixed in 2.7.2.

  • CVE-2026-33070LowMar 20, 2026
    risk 0.17cvss 3.7epss 0.00

    FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, a missing-authentication vulnerability in the deleteShareLink endpoint allows any unauthenticated user to delete arbitrary file share links by providing only the share token, causing denial…

  • CVE-2023-50263LowDec 12, 2023
    risk 0.17cvss 3.7epss 0.01

    Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 1.x and 2.0.x prior to 1.6.7 and 2.0.6, the URLs `/files/get/?name=...` and…

  • CVE-2022-3675LowNov 3, 2022
    risk 0.17cvss 2.6epss 0.00

    Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the GRUB command-line, modify kernel command-line arguments, or boot non-default OSTree deployments. Recent Fedora CoreOS releases…