VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 36 of 150
  • CVE-2026-47281CriJun 9, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2024-27892CriJun 4, 2026
    risk 0.62cvss 9.6epss 0.00

    Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.

  • CVE-2026-44211CriJun 1, 2026
    risk 0.62cvss 9.6epss 0.00

    Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly available patches.

  • CVE-2025-12548CriJan 13, 2026
    risk 0.62cvss 9.0epss 0.01

    A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API…

  • CVE-2025-48469CriJun 24, 2025
    risk 0.62cvss 9.6epss 0.00

    Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation.

  • CVE-2024-12106CriDec 31, 2024
    risk 0.62cvss 9.4epss 0.10

    In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.

  • CVE-2024-40087CriOct 21, 2024
    risk 0.62cvss 9.6epss 0.00

    Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP service on port 5432 allows remote, unauthenticated attackers to gain administrative access over the router.

  • CVE-2024-9164CriOct 11, 2024
    risk 0.62cvss 9.6epss 0.01

    An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

  • CVE-2024-23618CriJan 26, 2024
    risk 0.62cvss 9.6epss 0.01

    An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root.

  • CVE-2021-25094HigApr 25, 2022
    risk 0.62cvss 8.1epss 0.83

    The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass…

  • CVE-2021-36779CriDec 17, 2021
    risk 0.62cvss 9.6epss 0.01

    A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions…

  • CVE-2019-5591MedKEVAug 14, 2020
    risk 0.62cvss 6.5epss 0.18

    A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

  • CVE-2026-14525CriAug 13, 2026
    risk 0.61cvss 9.4epss 0.01

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.

  • CVE-2026-50516CriAug 11, 2026
    risk 0.61cvss 9.4epss 0.01

    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-61203CriJul 21, 2026
    risk 0.61cvss 9.4epss 0.00

    Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft…

  • CVE-2026-40702CriJun 25, 2026
    risk 0.61cvss 9.4epss 0.00

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is…

  • CVE-2026-11535CriJun 12, 2026
    risk 0.61cvss epss 0.00

    An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device.

  • CVE-2026-45087CriMay 27, 2026
    risk 0.61cvss 10.0epss 0.01

    Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to 0.0.0.0:6664 by default and requires no API key unless the operator explicitly passes --api-key.…

  • CVE-2026-44592CriMay 14, 2026
    risk 0.61cvss 9.4epss 0.00

    Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone who can reach /proto can register as a worker without any credentials by sending a fresh, never-registered worker UUID. The…

  • CVE-2026-3893CriApr 28, 2026
    risk 0.61cvss 9.4epss 0.00

    The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its configuration and operational functions without needing credentials.