VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 39 of 150
  • CVE-2020-7048CriJan 16, 2020
    risk 0.61cvss 9.1epss 0.23

    The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a…

  • CVE-2019-17354CriOct 9, 2019
    risk 0.61cvss 9.4epss 0.01

    wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify data fields of the page.

  • CVE-2019-10919CriMay 14, 2019
    risk 0.61cvss 9.4epss 0.03

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Attackers with access to port 10005/tcp could perform device reconfigurations and obtain project files from the devices. The system manual recommends to protect access to this port.…

  • CVE-2019-6538CriMar 25, 2019
    risk 0.61cvss 9.3epss 0.01

    The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D…

  • CVE-2019-6447HigJan 16, 2019
    risk 0.61cvss 8.1epss 0.64

    The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once,…

  • CVE-2026-71566CriAug 17, 2026
    risk 0.60cvss 9.3epss 0.00

    FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to validate them. However, KubeVirt relies on a KUBECONFIG file mounted to the container and completely ignores the credentials. This…

  • CVE-2026-59506CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    CWE-306: Missing Authentication for Critical Function

  • CVE-2025-15681CriAug 10, 2026
    risk 0.60cvss epss 0.00

    TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected functionality through the /index.asp endpoint without providing valid…

  • CVE-2026-62241CriJul 17, 2026
    risk 0.60cvss 9.1epss 0.07

    clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId values without authentication, a…

  • CVE-2026-46912CriJun 17, 2026
    risk 0.60cvss 9.3epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-28766CriApr 3, 2026
    risk 0.60cvss 9.3epss 0.00

    A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

  • CVE-2026-3356CriMar 31, 2026
    risk 0.60cvss epss 0.00

    The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. Because the device provides no mechanism to enable or configure authentication, the issue is inherent to its design…

  • CVE-2026-33032CriMar 30, 2026
    risk 0.60cvss 9.8epss 0.38

    Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired()…

  • CVE-2026-2417CriMar 24, 2026
    risk 0.60cvss epss 0.01

    A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privileges.

  • CVE-2026-26190CriFeb 13, 2026
    risk 0.60cvss 9.8epss 0.37

    Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from…

  • CVE-2026-25895CriFeb 9, 2026
    risk 0.60cvss 9.8epss 0.04

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This…

  • CVE-2026-1341CriFeb 3, 2026
    risk 0.60cvss epss 0.00

    Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.

  • CVE-2025-69970CriFeb 3, 2026
    risk 0.60cvss 9.3epss 0.00

    FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access…

  • CVE-2026-25137CriFeb 2, 2026
    risk 0.60cvss 9.1epss 0.10

    The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentication. This allows unauthorized actors to delete and download the entire database, including…

  • CVE-2026-24728CriJan 30, 2026
    risk 0.60cvss epss 0.00

    A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to access exposed administrative functionality without prior authentication.