VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,337)

page 42 of 167
  • CVE-2026-26288CriMar 6, 2026
    risk 0.61cvss 9.4epss 0.01

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging…

  • CVE-2026-26051CriMar 6, 2026
    risk 0.61cvss 9.4epss 0.01

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging…

  • CVE-2026-22552CriMar 6, 2026
    risk 0.61cvss 9.4epss 0.01

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging…

  • CVE-2026-27028CriFeb 27, 2026
    risk 0.61cvss 9.4epss 0.01

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging…

  • CVE-2026-27772CriFeb 27, 2026
    risk 0.61cvss 9.4epss 0.01

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging…

  • CVE-2026-27767CriFeb 27, 2026
    risk 0.61cvss 9.4epss 0.01

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging…

  • CVE-2026-25851CriFeb 27, 2026
    risk 0.61cvss 9.4epss 0.01

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging…

  • CVE-2026-24731CriFeb 27, 2026
    risk 0.61cvss 9.4epss 0.01

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging…

  • CVE-2026-20781CriFeb 27, 2026
    risk 0.61cvss 9.4epss 0.01

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging…

  • CVE-2025-70141CriFeb 18, 2026
    risk 0.61cvss 9.4epss 0.01

    SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An…

  • CVE-2026-25895CriFeb 9, 2026
    risk 0.61cvss 9.8epss 0.11

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This…

  • CVE-2025-59090CriJan 26, 2026
    risk 0.61cvss —epss 0.01

    On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sending requests. Therefore, network access to the exos server allows e.g. the creation of arbitrary access log events as well as querying the 2FA PINs associated…

  • CVE-2025-52024CriJan 23, 2026
    risk 0.61cvss 9.4epss 0.00

    A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated users. By accessing specific URLs, an attacker is presented with a directory-style index listing all available backend services and…

  • CVE-2025-54816CriJan 22, 2026
    risk 0.61cvss 9.4epss 0.00

    This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unauthorized users to establish connections. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized …

  • CVE-2026-23746CriJan 15, 2026
    risk 0.61cvss —epss 0.01

    Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the SmartCardController service (DCG.SmartCardControllerService.exe). The service…

  • CVE-2026-0625CriJan 5, 2026
    risk 0.61cvss —epss 0.01

    Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can…

  • CVE-2025-13607CriDec 10, 2025
    risk 0.61cvss 9.4epss 0.01

    A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

  • CVE-2025-34414CriDec 9, 2025
    risk 0.61cvss —epss 0.01

    Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the Legacy Remoting Service that is enabled by default. The service registers a TCP…

  • CVE-2025-65112CriNov 29, 2025
    risk 0.61cvss 9.4epss 0.00

    PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing, privilege escalation,…

  • CVE-2025-20358CriNov 5, 2025
    risk 0.61cvss 9.4epss 0.01

    A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution. This vulnerability is due to…