VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,961)

page 5 of 149
  • CVE-2026-30824CriMar 7, 2026
    risk 0.67cvss 9.8epss 0.36

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to privileged container…

  • CVE-2026-2624CriFeb 25, 2026
    risk 0.67cvss 9.8epss 0.02

    Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass. This issue affects Antikor Next Generation Firewall (NGFW): from v.2.0.1298 before v.2.0.1301.

  • CVE-2012-10030CriAug 5, 2025
    risk 0.67cvss 9.8epss 0.02

    FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of the C:\ drive, and imposes no…

  • CVE-2025-34111CriJul 15, 2025
    risk 0.67cvss 9.8epss 0.02

    An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of…

  • CVE-2024-50477CriOct 28, 2024
    risk 0.67cvss 9.8epss 0.08

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.

  • CVE-2023-20126CriMay 4, 2023
    risk 0.67cvss 9.8epss 0.37

    A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade…

  • CVE-2020-6170CriJan 8, 2020
    risk 0.67cvss 9.8epss 0.07

    An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.

  • CVE-2019-18939CriNov 14, 2019
    risk 0.67cvss 9.8epss 0.41

    eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi and exec1.cgi scripts, which execute TCL script content from an HTTP POST…

  • CVE-2025-53118CriAug 25, 2025
    risk 0.66cvss 9.8epss 0.29

    An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.

  • CVE-2025-41656CriJul 1, 2025
    risk 0.66cvss 10.0epss 0.12

    An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default.

  • CVE-2024-10924CriNov 15, 2024
    risk 0.66cvss 9.8epss 0.82

    The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user'…

  • CVE-2022-45551CriMar 3, 2023
    risk 0.66cvss 9.8epss 0.23

    An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.

  • CVE-2020-13382CriJul 1, 2020
    risk 0.66cvss 9.1epss 0.53

    openSIS through 7.4 has Incorrect Access Control.

  • CVE-2020-9480CriJun 23, 2020
    risk 0.66cvss 9.8epss 0.29

    In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the…

  • CVE-2019-18938CriNov 14, 2019
    risk 0.66cvss 9.8epss 0.34

    eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload upload and the testtcl.cgi script for its execution.

  • CVE-2019-18937CriNov 14, 2019
    risk 0.66cvss 9.8epss 0.34

    eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi script, which executes TCL script content from an HTTP POST request.

  • CVE-2026-58115CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to…

  • CVE-2026-63508CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.00

    Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-60365CriJul 21, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated…

  • CVE-2026-10577CriJul 14, 2026
    risk 0.65cvss epss 0.00

    A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If…