CWE-306— Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.— MITRE CWE catalog
3,492 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 15 of 70
- CVE-2024-10924CRITICALCVSS 9.8EG 9.82024-11-15
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with…
- CVE-2024-40404CRITICALCVSS 9.8EG 9.82024-11-13
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.
- CVE-2024-10284CRITICALCVSS 9.8EG 9.82024-11-09
The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This is due to hardcoded encryption key in the 'ce21_authentication_phrase' function. This makes it possible for unauthenti…
- CVE-2024-50489CRITICALCVSS 9.8EG 9.82024-10-28
Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through <= 1.0.45.
- CVE-2024-50487CRITICALCVSS 9.8EG 9.82024-10-28
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authentication Bypass.This issue affects MaanStore API: from n/a through <= 1.0.1.
- CVE-2024-50486CRITICALCVSS 9.8EG 9.82024-10-28
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through <= 1.0.5.
- CVE-2024-50477CRITICALCVSS 9.8EG 9.82024-10-28
Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.
- CVE-2024-10386CRITICALCVSS 9.8EG 9.82024-10-25
CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulatio…
- CVE-2024-49604CRITICALCVSS 9.8EG 9.82024-10-20
Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.
- CVE-2024-49328CRITICALCVSS 9.8EG 9.82024-10-20
Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through <= 1.0.0.
- CVE-2024-45274CRITICALCVSS 9.8EG 9.82024-10-15
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
- CVE-2024-9984CRITICALCVSS 9.8EG 9.82024-10-15
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.
- CVE-2024-8943CRITICALCVSS 9.8EG 9.82024-10-08
The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the user being supplied during the booking customer step. This makes it possib…
- CVE-2024-9289CRITICALCVSS 9.8EG 9.82024-10-01
The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a u…
- CVE-2024-46293CRITICALCVSS 9.8EG 9.82024-09-30
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a vali…
- CVE-2024-8456CRITICALCVSS 9.8EG 9.82024-09-30
Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining …
- CVE-2024-8310CRITICALCVSS 9.8EG 9.82024-09-27
OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.
- CVE-2024-6981CRITICALCVSS 9.8EG 9.82024-09-27
OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication.
- CVE-2024-8277CRITICALCVSS 9.8EG 9.82024-09-11
The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating what user transient is being used in the lo…
- CVE-2024-7015CRITICALCVSS 9.8EG 9.82024-09-09
Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse. This issue affects PassBox: before v1.2.
- CVE-2024-8584CRITICALCVSS 9.8EG 9.82024-09-09
Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.
- CVE-2024-4428CRITICALCVSS 9.8EG 9.82024-08-29
Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users. This issue affects Managment Portal: through 21.05.2024.
- CVE-2024-36445CRITICALCVSS 9.8EG 9.82024-08-22
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.
- CVE-2024-42462CRITICALCVSS 9.8EG 9.82024-08-16
Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.
- CVE-2024-7503CRITICALCVSS 9.8EG 9.82024-08-12
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' funct…
- CVE-2024-7007CRITICALCVSS 9.8EG 9.82024-07-25
Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.
- CVE-2024-38437CRITICALCVSS 9.8EG 9.82024-07-21
D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel
- CVE-2024-6422CRITICALCVSS 9.8EG 9.82024-07-10
An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.
- CVE-2024-0949CRITICALCVSS 9.8EG 9.82024-06-27
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.
- CVE-2024-32735CRITICALCVSS 9.8EG 9.82024-05-14
An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the applicatio…
- CVE-2023-42121CRITICALCVSS 9.8EG 9.82024-05-03
Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is not required to exploit th…
- CVE-2023-39457CRITICALCVSS 9.8EG 9.82024-05-03
Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not req…
- CVE-2023-51478CRITICALCVSS 9.8EG 9.82024-04-25
Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.
- CVE-2024-21014CRITICALCVSS 9.8EG 9.82024-04-16
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows una…
- CVE-2024-3701CRITICALCVSS 9.8EG 9.82024-04-15
The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.
- CVE-2024-3777CRITICALCVSS 9.8EG 9.82024-04-15
The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.
- CVE-2023-1083CRITICALCVSS 9.8EG 9.82024-04-09
An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.
- CVE-2024-31218CRITICALCVSS 9.8EG 9.82024-04-05
Webhood is a self-hosted URL scanner used analyzing phishing and malicious sites. Webhood's backend container images in versions 0.9.0 and earlier are subject to Missing Authentication for Critical Function vulnerability. This vulnerabilit…
- CVE-2024-2921CRITICALCVSS 9.8EG 9.82024-03-26
Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.
- CVE-2024-25995CRITICALCVSS 9.8EG 9.82024-03-12
An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation.
- CVE-2024-23917CRITICALCVSS 9.8EG 9.82024-02-06
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
- CVE-2023-5716CRITICALCVSS 9.8EG 9.82024-01-19
ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission.
- CVE-2023-49255CRITICALCVSS 9.8EG 9.82024-01-12
The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. If any other user is currently logged in, the anonymous user…
- CVE-2023-51987CRITICALCVSS 9.8EG 9.82024-01-11
D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords.
- CVE-2023-29485CRITICALCVSS 9.8EG 9.82023-12-21
An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to bypass network filtering, execute arbitrary code, and obtain sensitive information via DarkLayer Guard th…
- CVE-2023-49693CRITICALCVSS 9.8EG 9.82023-11-29
NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.
- CVE-2023-47674CRITICALCVSS 9.8EG 9.82023-11-16
Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only …
- CVE-2023-34060CRITICALCVSS 9.8EG 9.82023-11-14
VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a maliciou…
- CVE-2023-41351CRITICALCVSS 9.8EG 9.82023-11-03
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for …
- CVE-2023-46249CRITICALCVSS 9.8EG 9.82023-10-31
authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any aut…
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →