VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 64 of 150
  • CVE-2025-61778CriOct 6, 2025
    risk 0.53cvss epss 0.00

    Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enabled via our `akka.remote.dot-netty.tcp` transport and this would correctly enforce private key validation on the server-side of…

  • CVE-2025-8450HigAug 19, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.

  • CVE-2025-7679HigAug 11, 2025
    risk 0.53cvss 8.1epss 0.00

    The ASPECT system allows users to bypass authentication. This issue affects all versions of ASPECT

  • CVE-2025-6763HigJun 27, 2025
    risk 0.53cvss 8.1epss 0.01

    A vulnerability was found in Comet System T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552 and H3531 1.60. Affected by this issue is some unknown functionality of the file /setupA.cfg of the component Web-based Management Interface. Performing manipulation results…

  • CVE-2025-3090HigJun 24, 2025
    risk 0.53cvss 8.2epss 0.00

    An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authentication for critical function.

  • CVE-2025-3319HigJun 20, 2025
    risk 0.53cvss 8.1epss 0.00

    IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result in access to unauthorized resources.

  • CVE-2025-41654HigMay 26, 2025
    risk 0.53cvss 8.2epss 0.00

    An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of returned data can trigger a reboot by the watchdog.

  • CVE-2025-25060HigApr 2, 2025
    risk 0.53cvss 8.2epss 0.00

    Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server where the product is running may be obtained and/or deleted by a remote unauthenticated attacker.

  • CVE-2024-8053HigMar 20, 2025
    risk 0.53cvss 8.2epss 0.01

    In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload,…

  • CVE-2024-10776HigDec 6, 2024
    risk 0.53cvss 8.2epss 0.00

    Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write files or load apps that use all features of the product available to a customer.

  • CVE-2024-49052HigNov 26, 2024
    risk 0.53cvss 8.2epss 0.01

    Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2024-5718HigNov 22, 2024
    risk 0.53cvss 8.1epss 0.01

    Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this…

  • CVE-2024-41967HigNov 18, 2024
    risk 0.53cvss 8.1epss 0.00

    A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack.

  • CVE-2024-40405HigNov 13, 2024
    risk 0.53cvss 8.1epss 0.00

    Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.

  • CVE-2024-47912HigOct 21, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to perform unauthorized data-access attacks due to missing authentication mechanisms. A successful exploit could…

  • CVE-2024-7628HigAug 15, 2024
    risk 0.53cvss 8.1epss 0.01

    The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.15.2. This is due to the use of loose comparison in the 'verify_id_token' function. This makes it possible for…

  • CVE-2024-21146HigJul 16, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-36470HigMay 29, 2024
    risk 0.53cvss 8.1epss 0.00

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases

  • CVE-2022-34321HigMar 12, 2024
    risk 0.53cvss 8.2epss 0.02

    Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics about live connections, along with the capability to modify the logging level of…

  • CVE-2023-5881HigJan 3, 2024
    risk 0.53cvss 8.2epss 0.01

    Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Garage Door Control Module Setup" and modify the Garage door's SSID settings.