VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,962)

page 130 of 149
  • CVE-2024-42178LowApr 17, 2025
    risk 0.16cvss 2.5epss 0.00

    HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk of misuse, manipulation, or unauthorized distribution.

  • CVE-2023-29063LowNov 28, 2023
    risk 0.16cvss 2.4epss 0.00

    The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat actor to insert a PCI card designed for memory capture. A threat actor can then isolate sensitive information such as a BitLocker encryption key from a dump of…

  • CVE-2022-23227CriKEVJan 14, 2022
    risk 0.16cvss 9.8epss 0.49

    NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite…

  • CVE-2020-25824LowOct 14, 2020
    risk 0.16cvss 2.4epss 0.01

    Telegram Desktop through 2.4.3 does not require passcode entry upon pushing the Export key within the Export Telegram Data wizard. The threat model is a victim who has voluntarily opened Export Wizard but is then distracted. An attacker then approaches the unattended desktop and…

  • CVE-2019-20598LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's learned words, and the clipboard contents, via the lock screen. The Samsung IDs are SVE-2018-12896, SVE-2018-12897 (May 2019).

  • CVE-2019-20595LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. Quick Panel allows enabling or disabling the Bluetooth stack without authentication. The Samsung ID is SVE-2019-14545 (July 2019).

  • CVE-2019-20579LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Gallery allows attackers to enable Location information sharing from the lock screen. The Samsung ID is SVE-2019-14462 (August 2019).

  • CVE-2019-20559LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery allows viewing of photos on the lock screen. The Samsung ID is SVE-2019-15055 (October 2019).

  • CVE-2019-8682LowDec 18, 2019
    risk 0.16cvss 2.4epss 0.00

    The issue was addressed with improved UI handling. This issue is fixed in iOS 12.4, watchOS 5.3. A user may inadvertently complete an in-app purchase while on the lock screen.

  • CVE-2026-60596LowJul 21, 2026
    risk 0.15cvss 2.3epss 0.00

    Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft…

  • CVE-2026-56164MedKEVJul 14, 2026
    risk 0.14cvss 5.3epss 0.22

    Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-27538LowApr 16, 2025
    risk 0.14cvss 2.2epss 0.00

    Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate MFA for other users, even if…

  • CVE-2023-4505LowSep 27, 2023
    risk 0.14cvss 2.2epss 0.01

    The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers,…

  • CVE-2021-39879LowOct 4, 2021
    risk 0.14cvss 2.2epss 0.00

    Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

  • CVE-2026-59715LowJul 9, 2026
    risk 0.13cvss 3.1epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured with always_connect=True. The ydoc:awareness:update and ydoc:document:leave Socket.IO handlers accepted collaborative-document…

  • CVE-2025-13870LowDec 2, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards…

  • CVE-2015-7559LowAug 1, 2019
    risk 0.11cvss 2.7epss 0.02

    It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

  • CVE-2014-9195Jan 17, 2015
    risk 0.09cvss epss 0.81

    Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.

  • CVE-2014-4872Oct 10, 2014
    risk 0.09cvss epss 0.80

    BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1) FileStorageService or (2)…

  • CVE-2022-3229CriFeb 6, 2023
    risk 0.08cvss 9.8epss 0.66

    Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated…