VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 153 of 169
  • CVE-2014-9195Jan 17, 2015
    risk 0.09cvss —epss 0.81

    Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.

  • CVE-2014-4872Oct 10, 2014
    risk 0.09cvss —epss 0.79

    BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1) FileStorageService or (2)…

  • CVE-2026-50608LowSep 17, 2026
    risk 0.08cvss —epss 0.00

    A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized…

  • CVE-2022-3229CriFeb 6, 2023
    risk 0.08cvss 9.8epss 0.66

    Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated…

  • CVE-2020-12492LowNov 25, 2024
    risk 0.07cvss —epss 0.00

    Improper handling of WiFi information by framework services can allow certain malicious applications to obtain sensitive information.

  • CVE-2023-4506LowSep 27, 2023
    risk 0.07cvss 2.2epss 0.01

    The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with…

  • CVE-2022-23944CriJan 25, 2022
    risk 0.06cvss 9.1epss 0.79

    User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

  • CVE-2009-1780May 22, 2009
    risk 0.03cvss —epss 0.04

    admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.

  • CVE-2024-6842HigMar 20, 2025
    risk 0.02cvss 7.5epss 0.31

    In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for search engines, which can be…

  • CVE-2007-0956Apr 6, 2007
    risk 0.02cvss —epss 0.30

    The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.

  • CVE-2026-78154Aug 24, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The endpoint is public on purpose and the invitation code is the credential.…

  • CVE-2026-75501Aug 21, 2026
    risk 0.00cvss —epss 0.01

    Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment.

  • CVE-2026-67594CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing…

  • CVE-2026-67208CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.04

    Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected…

  • CVE-2026-15978HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.01

    SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model…

  • CVE-2026-12722HigJul 30, 2026
    risk 0.00cvss 8.2epss 0.00

    Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2.

  • CVE-2026-54367HigJul 30, 2026
    risk 0.00cvss 8.6epss 0.00

    CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId…

  • CVE-2026-54365HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a…

  • CVE-2026-44101CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.

  • CVE-2026-44100CriJul 30, 2026
    risk 0.00cvss 9.4epss 0.01

    The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.