VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 42 of 150
  • CVE-2026-31242CriMay 12, 2026
    risk 0.59cvss 9.1epss 0.00

    The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE request that triggers a reset operation, leading to the execution of a DROP TABLE…

  • CVE-2026-22924CriMay 12, 2026
    risk 0.59cvss 9.1epss 0.00

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions. This could allow an attacker to disrupt normal operations or…

  • CVE-2026-27843CriApr 24, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authentication or server-side validation. By applying unsupported or disruptive values to recovery mechanisms and network…

  • CVE-2026-41176CriApr 23, 2026
    risk 0.59cvss 9.8epss 0.33

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. Starting in…

  • CVE-2026-34286CriApr 21, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise…

  • CVE-2026-34285CriApr 21, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise…

  • CVE-2026-34279CriApr 21, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via…

  • CVE-2026-32211CriApr 3, 2026
    risk 0.59cvss 9.1epss 0.01

    Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-30035CriMar 2, 2026
    risk 0.59cvss epss 0.00

    The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, without requiring a password or any other credentials. Obtaining a session ID is sufficient for session takeover and…

  • CVE-2025-70146CriFeb 18, 2026
    risk 0.59cvss 9.1epss 0.00

    Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected…

  • CVE-2026-25848CriFeb 9, 2026
    risk 0.59cvss 9.1epss 0.00

    In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible

  • CVE-2026-2234CriFeb 9, 2026
    risk 0.59cvss 9.1epss 0.00

    C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read and modify any user's mail content.

  • CVE-2026-1632CriFeb 3, 2026
    risk 0.59cvss 9.1epss 0.00

    MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify configuration settings, acquire device data or remotely reset the device.

  • CVE-2025-68715CriJan 8, 2026
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless…

  • CVE-2025-34224CriSep 29, 2025
    risk 0.59cvss 9.1epss 0.01

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) expose a set of PHP scripts under the `console_release` directory without requiring authentication. An unauthenticated…

  • CVE-2025-34222CriSep 29, 2025
    risk 0.59cvss 9.1epss 0.00

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) expose four admin routes – /admin/hp/cert_upload, /admin/hp/cert_delete, /admin/certs/ca, and…

  • CVE-2025-59345CriSep 17, 2025
    risk 0.59cvss 9.1epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Manager web UI are accessible without authentication. Any user with network access to the Manager can create, delete, and modify…

  • CVE-2025-30041CriAug 27, 2025
    risk 0.59cvss epss 0.00

    The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl" expose data containing session IDs.

  • CVE-2025-30040CriAug 27, 2025
    risk 0.59cvss epss 0.00

    The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "/cgi-bin/CliniNET.prd/utils/userlogxls.pl" endpoint.

  • CVE-2025-30039CriAug 27, 2025
    risk 0.59cvss epss 0.00

    Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, including users with admin privileges.