CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
3,492 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 14 of 70
- CVE-2025-8279CRITICALCVSS 9.8EG 9.82025-07-28
Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution
- CVE-2025-6260CRITICALCVSS 9.8EG 9.82025-07-24
The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the Internet via a router with port forwarding set up, to gain direct a…
- CVE-2025-7897CRITICALCVSS 9.8EG 9.82025-07-20
A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file app/controllers/base.py of the component API Endpoint. The manipulation leads …
- CVE-2025-7862CRITICALCVSS 9.8EG 9.82025-07-20
A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation …
- CVE-2025-34111CRITICALCVSS 9.8EG 9.82025-07-15
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute m…
- CVE-2025-40736CRITICALCVSS 9.8EG 9.82025-07-08
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modification of administrative credentials. This could allow an unauthenticated attacker to re…
- CVE-2025-45814CRITICALCVSS 9.8EG 9.82025-07-02
Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to execute a session hijacking attack.
- CVE-2025-34071CRITICALCVSS 9.8EG 9.82025-07-02
A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code through the firmware upgrade feature. The system upgrade mechanism accepts unsigned .img file…
- CVE-2025-34070CRITICALCVSS 9.8EG 9.82025-07-02
A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible for integration with GFI AppManager, ex…
- CVE-2025-34069CRITICALCVSS 9.8EG 9.82025-07-02
An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the GFIAgent service. The non-transparent proxy on TCP port 3128 can be used to forward unauthe…
- CVE-2025-5310CRITICALCVSS 9.8EG 9.82025-06-27
Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, deleted, or modified, potentially leading to remote c…
- CVE-2025-3699CRITICALCVSS 9.8EG 9.82025-06-26
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A all versions, GB-50 all versions, GB-50A all versions, GB-24A all versions, G-150AD all versions, A…
- CVE-2025-5906CRITICALCVSS 9.8EG 9.82025-06-10
A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. T…
- CVE-2025-49652CRITICALCVSS 9.8EG 9.82025-06-09
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.
- CVE-2025-1907CRITICALCVSS 9.8EG 9.82025-05-30
Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if connected.
- CVE-2025-22252CRITICALCVSS 9.8EG 9.82025-05-28
A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an exi…
- CVE-2025-41651CRITICALCVSS 9.8EG 9.82025-05-27
Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially enabling unauthorized upload or download of configuration files and leading to full system c…
- CVE-2025-4555CRITICALCVSS 9.8EG 9.82025-05-12
The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system functions. These functions include opening gates…
- CVE-2025-46275CRITICALCVSS 9.8EG 9.82025-04-24
WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without knowing any existing credentials.
- CVE-2025-30727CRITICALCVSS 9.8EG 9.82025-04-15
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network a…
- CVE-2025-2567CRITICALCVSS 9.8EG 9.82025-04-15
An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling of ATG monitoring. This would result in potential safety hazards in fuel storage and transportation.
- CVE-2024-13553CRITICALCVSS 9.8EG 9.82025-04-01
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host header to determine if …
- CVE-2024-8196CRITICALCVSS 9.8EG 9.82025-03-20
In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to per…
- CVE-2024-13771CRITICALCVSS 9.8EG 9.82025-03-14
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of user validation before changing a password. This…
- CVE-2025-1315CRITICALCVSS 9.8EG 9.82025-03-07
The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. This is due to the plugin not properly validating a user's identity prior to updating their password…
- CVE-2025-27647CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Addition of Partial Admin Users Without Authentication V-2024-002.
- CVE-2025-27642CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Unauthenticated Driver Package Editing V-2024-008.
- CVE-2025-24924CRITICALCVSS 9.8EG 9.82025-03-05
Certain functionality within GMOD Apollo does not require authentication when passed with an administrative username
- CVE-2025-1283CRITICALCVSS 9.8EG 9.82025-02-13
The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly navigating to the main page.
- CVE-2025-0896CRITICALCVSS 9.8EG 9.82025-02-13
Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.
- CVE-2025-26359CRITICALCVSS 9.8EG 9.82025-02-12
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset user PINs via crafted HTTP requests.
- CVE-2025-26347CRITICALCVSS 9.8EG 9.82025-02-12
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to edit user permissions via crafted HTTP requests.
- CVE-2025-26345CRITICALCVSS 9.8EG 9.82025-02-12
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to edit user group permissions via crafted HTTP request…
- CVE-2025-26344CRITICALCVSS 9.8EG 9.82025-02-12
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable passwordless guest mode via crafted HTT…
- CVE-2025-26342CRITICALCVSS 9.8EG 9.82025-02-12
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to create arbitrary users, including administrators…
- CVE-2025-26341CRITICALCVSS 9.8EG 9.82025-02-12
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset arbitrary user passwords via crafted HTTP …
- CVE-2025-26339CRITICALCVSS 9.8EG 9.82025-02-12
A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availa…
- CVE-2024-36555CRITICALCVSS 9.8EG 9.82025-02-06
Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allows malicious users to change …
- CVE-2024-9644CRITICALCVSS 9.8EG 9.82025-02-04
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the administrative web server. Authentication is not enforced on some administrative functionality when using the "bapply.cgi" en…
- CVE-2024-12857CRITICALCVSS 9.8EG 9.82025-01-22
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it po…
- CVE-2025-21535CRITICALCVSS 9.8EG 9.82025-01-21
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with …
- CVE-2025-21524CRITICALCVSS 9.8EG 9.82025-01-21
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticat…
- CVE-2025-0456CRITICALCVSS 9.8EG 9.82025-01-16
The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access the specific administrative functionality to retrieve * all accounts and passwords.
- CVE-2024-12847CRITICALCVSS 9.8EG 9.82025-01-10
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpo…
- CVE-2024-54984CRITICALCVSS 9.8EG 9.82024-12-19
An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the supplier.
- CVE-2024-54983CRITICALCVSS 9.8EG 9.82024-12-19
An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.
- CVE-2024-50375CRITICALCVSS 9.8EG 9.82024-11-26
A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can …
- CVE-2024-47138CRITICALCVSS 9.8EG 9.82024-11-22
The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.
- CVE-2024-38643CRITICALCVSS 9.8EG 9.82024-11-22
A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed …
- CVE-2024-21855CRITICALCVSS 9.8EG 9.82024-11-21
A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vul…
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →