VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 54 of 150
  • CVE-2025-49652CriJun 9, 2025
    risk 0.57cvss 9.8epss 0.00

    Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.

  • CVE-2025-3759HigMay 8, 2025
    risk 0.57cvss epss 0.00

    Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about…

  • CVE-2025-3758HigMay 8, 2025
    risk 0.57cvss epss 0.00

    WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Returned configuration includes cleartext password. The vendor was contacted early about this disclosure but did not respond in any way.

  • CVE-2024-9658HigMar 7, 2025
    risk 0.57cvss 8.8epss 0.00

    The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email…

  • CVE-2025-21515HigJan 21, 2025
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2024-42456HigDec 4, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate used for authentication on a specific port. This can result…

  • CVE-2024-40717HigDec 4, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed…

  • CVE-2024-50381HigDec 2, 2024
    risk 0.57cvss epss 0.01

    A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and can make a request to unclaim it from its original…

  • CVE-2024-52438HigNov 20, 2024
    risk 0.57cvss 8.8epss 0.00

    Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escalation.This issue affects de:branding: from n/a through <= 1.0.2.

  • CVE-2024-52437HigNov 20, 2024
    risk 0.57cvss 8.8epss 0.00

    Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System banner-system allows Privilege Escalation.This issue affects Banner System: from n/a through <= 1.0.0.

  • CVE-2024-41969HigNov 18, 2024
    risk 0.57cvss 8.8epss 0.00

    A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.

  • CVE-2024-10284CriNov 9, 2024
    risk 0.57cvss 9.8epss 0.00

    The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This is due to hardcoded encryption key in the 'ce21_authentication_phrase' function. This makes it possible for unauthenticated attackers to log in as any…

  • CVE-2024-50488HigOct 28, 2024
    risk 0.57cvss 8.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affects Token Login: from n/a through <= 1.0.3.

  • CVE-2024-10002HigOct 22, 2024
    risk 0.57cvss 8.8epss 0.01

    The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. This is due to insufficient validation and capability check on the 'rover_idx_refresh_social_callback' function. This makes it possible for authenticated…

  • CVE-2024-49399HigOct 17, 2024
    risk 0.57cvss epss 0.00

    The affected product is vulnerable to an attacker being able to use commands without providing a password which may allow an attacker to leak information.

  • CVE-2023-22650HigOct 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which…

  • CVE-2024-9522HigOct 10, 2024
    risk 0.57cvss 8.8epss 0.00

    The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect authentication and capability checking in the 'ajax_masq_login' function. This makes it possible for authenticated attackers,…

  • CVE-2024-43488HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.01

    Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.

  • CVE-2024-47130HigSep 26, 2024
    risk 0.57cvss 8.8epss 0.00

    The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to update your app to the current release for enhanced encryption protocols.

  • CVE-2024-45075HigSep 4, 2024
    risk 0.57cvss 8.8epss 0.00

    IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication.