VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 146 of 169
  • CVE-2020-27902MedDec 8, 2020
    risk 0.30cvss 4.6epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2. A person with physical access to an iOS device may be able to access stored passwords without authentication.

  • CVE-2020-25048MedAug 31, 2020
    risk 0.30cvss 4.6epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Quick Share feature allows unauthenticated downloads, aka file injection. The Samsung ID is SVE-2020-17760 (August 2020).

  • CVE-2019-5451MedJul 30, 2019
    risk 0.30cvss 4.6epss 0.00

    Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.

  • CVE-2017-2708MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by special steps. Due to missing authentication of the 'Find Phone'…

  • CVE-2026-60884MedAug 18, 2026
    risk 0.29cvss 4.4epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-7113MedApr 27, 2026
    risk 0.29cvss 5.6epss 0.01

    A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication.…

  • CVE-2026-3194MedFeb 25, 2026
    risk 0.29cvss 4.5epss 0.00

    A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of the component RPC Server Master Passphrase Handler. This manipulation causes missing authentication. The attack can only be executed locally. The attack's…

  • CVE-2025-47272MedJun 2, 2025
    risk 0.29cvss 5.5epss 0.00

    The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to delete their accounts without requiring password re-authentication. An attacker with temporary access to an authenticated session (e.g., on a shared/public…

  • CVE-2012-2736MedDec 26, 2019
    risk 0.29cvss 4.4epss 0.00

    In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.

  • CVE-2026-104181MedOct 1, 2026
    risk 0.28cvss 5.4epss 0.00

    Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an…

  • CVE-2026-103053MedSep 30, 2026
    risk 0.28cvss 5.4epss 0.00

    AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action…

  • CVE-2026-11838MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Reservation System allows Input Data Manipulation. This issue affects Library Reservation System: before…

  • CVE-2026-9033MedAug 20, 2026
    risk 0.28cvss 4.3epss 0.00

    An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access.  …

  • CVE-2026-47671MedJul 21, 2026
    risk 0.28cvss 5.4epss 0.00

    Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` exposes the Mimir GraphQL API with dummy authorization directives and permissive CORS. When a developer is running the local…

  • CVE-2026-47212MedJul 14, 2026
    risk 0.28cvss 5.3epss 0.02

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received the configured webhook secret but ignored the X-Twilio-Signature HMAC header, allowing unauthenticated…

  • CVE-2026-45397MedMay 15, 2026
    risk 0.28cvss 5.3epss 0.01

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns live RAG pipeline configuration to any unauthenticated HTTP client. No Authorization header, cookie, or API key is required. Every…

  • CVE-2025-15509MedFeb 27, 2026
    risk 0.28cvss 4.3epss 0.00

    The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2023-47232MedDec 21, 2025
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in mojofywp WP Affiliate Disclosure wp-affiliate-disclosure.This issue affects WP Affiliate Disclosure: from n/a through 1.2.6.

  • CVE-2025-64056MedDec 5, 2025
    risk 0.28cvss 4.3epss 0.00

    File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.

  • CVE-2025-63435MedNov 24, 2025
    risk 0.28cvss 4.3epss 0.00

    Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any authentication. This allows an unauthenticated remote attacker to freely…