CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (3,362)
page 134 of 169| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-4018 | Med | 0.35 | 5.3 | 0.01 | Apr 28, 2025 | A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue affects the function addCrawlSource of the file novel-crawl/src/main/java/com/java2nb/novel/controller/CrawlController.java. The… | ||
| CVE-2025-4015 | Med | 0.35 | 5.3 | 0.01 | Apr 28, 2025 | A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issue is the function list of the file novel-system/src/main/java/com/java2nb/system/controller/SessionController.java. The… | ||
| CVE-2024-39773 | Med | 0.35 | 5.3 | 0.01 | Jan 14, 2025 | An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability. | ||
| CVE-2024-33616 | Med | 0.35 | 5.3 | 0.01 | Nov 26, 2024 | Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporation states the telnet feature is implemented on older models only, and is planning to provide the firmware update to remove the… | ||
| CVE-2024-41968 | Med | 0.35 | 5.4 | 0.00 | Nov 18, 2024 | A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS. | ||
| CVE-2024-8320 | Med | 0.35 | 5.3 | 0.01 | Sep 10, 2024 | Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices. | ||
| CVE-2023-37325 | Med | 0.35 | 5.4 | 0.00 | May 7, 2024 | D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to make unauthorized changes to device configuration on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this… | ||
| CVE-2023-39466 | Med | 0.35 | 5.3 | 0.01 | May 3, 2024 | Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not… | ||
| CVE-2024-2076 | Med | 0.35 | 5.3 | 0.01 | Mar 1, 2024 | A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file booking.php/owner.php/tenant.php. The manipulation leads to missing authentication. The attack may be… | ||
| CVE-2024-21619 | Med | 0.35 | 5.3 | 0.01 | Jan 25, 2024 | A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access… | ||
| CVE-2023-29060 | Med | 0.35 | 5.4 | 0.00 | Nov 28, 2023 | The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited, a threat actor with physical access to the workstation could gain access to system information and potentially exfiltrate data. | ||
| CVE-2023-46819 | Med | 0.35 | 5.3 | 0.02 | Nov 7, 2023 | Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09. Users are recommended to upgrade to version 18.12.09 | ||
| CVE-2023-42845 | Med | 0.35 | 5.3 | 0.01 | Oct 25, 2023 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. Photos in the Hidden Photos Album may be viewed without authentication. | ||
| CVE-2023-38523 | Med | 0.35 | 5.3 | 0.01 | Jul 20, 2023 | The web interface on multiple Samsung Harman AMX N-Series devices allows directory listing for the /tmp/ directory, without authentication, exposing sensitive information such as the command history and screenshot of the file being processed. This affects N-Series N1115… | ||
| CVE-2022-36249 | Med | 0.35 | 5.4 | 0.00 | May 30, 2023 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to… | ||
| CVE-2023-23545 | Med | 0.35 | 5.3 | 0.01 | May 23, 2023 | Missing authentication for critical function exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may allow a remote unauthenticated attacker to alter the product settings without authentication. Affected products and versions are as follows: T&D Corporation… | ||
| CVE-2023-27571 | Med | 0.35 | 5.3 | 0.01 | Apr 15, 2023 | An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionality does not check the session cookie. Thus, an attacker can download all log files. | ||
| CVE-2023-28470 | Med | 0.35 | 5.3 | 0.01 | Mar 23, 2023 | In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication. | ||
| CVE-2023-21743 | Med | 0.35 | 5.3 | 0.01 | Jan 10, 2023 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | ||
| CVE-2022-45432 | Med | 0.35 | 5.3 | 0.01 | Dec 27, 2022 | Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices in range of IPs… |
- risk 0.35cvss 5.3epss 0.01
A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue affects the function addCrawlSource of the file novel-crawl/src/main/java/com/java2nb/novel/controller/CrawlController.java. The…
- risk 0.35cvss 5.3epss 0.01
A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issue is the function list of the file novel-system/src/main/java/com/java2nb/system/controller/SessionController.java. The…
- risk 0.35cvss 5.3epss 0.01
An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.
- risk 0.35cvss 5.3epss 0.01
Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporation states the telnet feature is implemented on older models only, and is planning to provide the firmware update to remove the…
- risk 0.35cvss 5.4epss 0.00
A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.
- risk 0.35cvss 5.3epss 0.01
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
- risk 0.35cvss 5.4epss 0.00
D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to make unauthorized changes to device configuration on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this…
- risk 0.35cvss 5.3epss 0.01
Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not…
- risk 0.35cvss 5.3epss 0.01
A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file booking.php/owner.php/tenant.php. The manipulation leads to missing authentication. The attack may be…
- risk 0.35cvss 5.3epss 0.01
A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access…
- risk 0.35cvss 5.4epss 0.00
The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited, a threat actor with physical access to the workstation could gain access to system information and potentially exfiltrate data.
- risk 0.35cvss 5.3epss 0.02
Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09. Users are recommended to upgrade to version 18.12.09
- risk 0.35cvss 5.3epss 0.01
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. Photos in the Hidden Photos Album may be viewed without authentication.
- risk 0.35cvss 5.3epss 0.01
The web interface on multiple Samsung Harman AMX N-Series devices allows directory listing for the /tmp/ directory, without authentication, exposing sensitive information such as the command history and screenshot of the file being processed. This affects N-Series N1115…
- risk 0.35cvss 5.4epss 0.00
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to…
- risk 0.35cvss 5.3epss 0.01
Missing authentication for critical function exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may allow a remote unauthenticated attacker to alter the product settings without authentication. Affected products and versions are as follows: T&D Corporation…
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionality does not check the session cookie. Thus, an attacker can download all log files.
- risk 0.35cvss 5.3epss 0.01
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
- risk 0.35cvss 5.3epss 0.01
Microsoft SharePoint Server Security Feature Bypass Vulnerability
- risk 0.35cvss 5.3epss 0.01
Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices in range of IPs…