VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 47 of 150
  • CVE-2025-49596CriJun 13, 2025
    risk 0.58cvss epss 0.45

    The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP…

  • CVE-2025-1701HigJun 4, 2025
    risk 0.58cvss epss 0.01

    CVE-2025-1701 is a high-severity vulnerability in the MIM Admin service. An attacker could exploit this vulnerability by sending a specially crafted request over the RMI interface to execute arbitrary code with the privileges of the MIM Admin service. The RMI interface is only…

  • CVE-2024-56799CriDec 30, 2024
    risk 0.58cvss 10.0epss 0.01

    Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7.

  • CVE-2023-41183HigMay 3, 2024
    risk 0.58cvss 8.8epss 0.15

    NETGEAR Orbi 760 SOAP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR Orbi 760 routers. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2022-25008HigMar 30, 2022
    risk 0.58cvss 8.8epss 0.04

    totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.

  • CVE-2019-17186HigOct 8, 2019
    risk 0.58cvss 8.8epss 0.06

    /var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code execution.

  • CVE-2019-9880CriJun 10, 2019
    risk 0.58cvss 9.1epss 0.35

    An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

  • CVE-2017-5637HigOct 10, 2017
    risk 0.58cvss 7.5epss 0.73

    Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue,…

  • CVE-2026-75854CriAug 18, 2026
    risk 0.57cvss 9.8epss

    ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can connect to the Redis port and execute arbitrary commands against any database on…

  • CVE-2026-75852CriAug 18, 2026
    risk 0.57cvss 9.8epss

    ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.

  • CVE-2026-73673HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher.…

  • CVE-2026-72822CriAug 14, 2026
    risk 0.57cvss 9.8epss 0.00

    The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely via ACL reads…

  • CVE-2026-72776CriAug 13, 2026
    risk 0.57cvss 9.8epss 0.01

    AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard…

  • CVE-2026-49827CriAug 13, 2026
    risk 0.57cvss 9.8epss 0.00

    WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open…

  • CVE-2026-49819CriAug 13, 2026
    risk 0.57cvss 9.8epss 0.01

    UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any…

  • CVE-2026-65941HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

  • CVE-2026-66875HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a…

  • CVE-2026-64921HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-72920CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.00

    SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser,…

  • CVE-2025-15683HigAug 10, 2026
    risk 0.57cvss epss 0.01

    TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attacker can invoke specific HTTP endpoints to reboot or reset the device, clear application data, or terminate the web server through a…