CWE-306: Missing Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

675
Total CVEs
325
Critical
243
High
8.5
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
78
2025
257
2024
104
2023
84
2022
53

Top Affected Vendors

1 Oracle 21
2 Sap 11
3 Socomec 10
4 Siemens 10
5 Q Free 10
6 Schneider Electric 9
7 Microsoft 9
8 Vasion 9
9 Dlink 8
10 Idattend 7

All Missing Authentication CVEs (675)

CVE-2025-54849
7.5

An unauthenticated denial-of-service vulnerability in Socomec DIRIS Digiware M-70 allows attackers to crash the device by sending a specially crafted ...

Dec 1, 2025
CVE-2025-34331
7.5

AudioCodes Fax Server and Auto-Attendant IVR appliances contain an unauthenticated file read vulnerability in the download.php script. Attackers can r...

Nov 19, 2025
CVE-2025-61756
7.5

This vulnerability allows unauthenticated attackers with network access via HTTP to cause a denial-of-service (DoS) condition in Oracle Financial Serv...

Oct 21, 2025
CVE-2025-61752
7.5

An unauthenticated remote attacker can exploit this vulnerability in Oracle WebLogic Server via HTTP/2 to cause a denial of service, resulting in serv...

Oct 21, 2025
CVE-2025-41703
7.5

An unauthenticated remote attacker can send a Modbus command to turn off the output of an Uninterruptible Power Supply (UPS), causing a denial of serv...

Oct 14, 2025
CVE-2025-59358
7.5

The Chaos Controller Manager in Chaos Mesh exposes an unauthenticated GraphQL debugging server that allows attackers to kill arbitrary processes in an...

Sep 15, 2025
CVE-2025-7970
7.5

A cryptographic implementation flaw in FactoryTalk Activation Manager allows attackers to decrypt network traffic. This vulnerability affects all syst...

Sep 9, 2025
CVE-2023-7308
7.5

The SecGate3600 firewall has an authentication bypass vulnerability in its user management endpoint that allows unauthenticated attackers to retrieve ...

Aug 27, 2025
CVE-2025-41689
7.5

This vulnerability allows unauthenticated remote attackers to access measurement data stored on affected devices without any password protection. It a...

Aug 19, 2025
CVE-2025-54864
7.5

This vulnerability allows unauthenticated API calls to trigger resource-intensive evaluations in Hydra, potentially causing denial of service attacks....

Aug 12, 2025
CVE-2025-30762
7.5

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to access sensitive data. I...

Jul 15, 2025
CVE-2025-48814
7.5

This vulnerability allows unauthorized attackers to bypass security features in Windows Remote Desktop Licensing Service by exploiting missing authent...

Jul 8, 2025
CVE-2024-8419
7.5

This vulnerability allows unauthorized remote attackers to trigger a fail-safe state on affected systems without authentication. Any system running th...

Jun 30, 2025
CVE-2025-6678
7.5

This vulnerability allows remote attackers to access sensitive information from Autel MaxiCharger AC Wallbox Commercial charging stations without auth...

Jun 25, 2025
CVE-2025-26468
7.5

CyberData 011209 Intercom has an authentication bypass vulnerability that allows unauthenticated attackers to access restricted features. This could l...

Jun 9, 2025
CVE-2025-5192
7.5

This vulnerability allows remote attackers to bypass authentication in Soar Cloud HRD Human Resource Management System client applications. Attackers ...

Jun 6, 2025
CVE-2025-29870
7.5

Missing authentication vulnerability in Wi-Fi AP UNIT 'AC-WPS-11ac series' allows remote unauthenticated attackers to access product configuration inf...

Apr 9, 2025
CVE-2025-25068
7.5

Mattermost fails to enforce multi-factor authentication (MFA) on plugin endpoints, allowing authenticated attackers to bypass MFA protections via API ...

Mar 21, 2025
CVE-2024-6842
EPSS 72.6% 7.5

This vulnerability allows unauthenticated attackers to access the /setup-complete API endpoint in Anything-LLM version 1.5.5, exposing sensitive syste...

Mar 20, 2025
CVE-2024-50630
7.5

This vulnerability allows remote attackers to obtain administrator credentials in Synology Drive Server due to missing authentication for a critical w...

Mar 19, 2025
CVE-2025-30111
7.5

This vulnerability allows unauthorized remote access to video footage and live streams from IROAD v9 dashcams. Attackers who gain initial access throu...

Mar 18, 2025
CVE-2025-26364
7.5

An unauthenticated remote attacker can disable authentication profile servers in Q-Free MaxTime traffic management systems by sending crafted HTTP req...

Feb 12, 2025
CVE-2025-26365
7.5

This vulnerability allows unauthenticated remote attackers to enable front panel authentication on Q-Free MaxTime systems via crafted HTTP requests. I...

Feb 12, 2025
CVE-2025-26366
7.5

An unauthenticated remote attacker can disable front panel authentication in Q-Free MaxTime systems via crafted HTTP requests. This affects all Q-Free...

Feb 12, 2025
CVE-2025-26363
7.5

This vulnerability allows unauthenticated remote attackers to enable authentication profile servers in Q-Free MaxTime traffic management systems via c...

Feb 12, 2025
CVE-2025-0355
7.5

A missing authentication vulnerability in multiple NEC Aterm router models allows attackers to retrieve Wi-Fi passwords without authentication. This a...

Jan 15, 2025
CVE-2024-13185
7.5

The MinigameCenter module has insufficient URL loading restrictions, allowing attackers to load arbitrary URLs and potentially leak sensitive informat...

Jan 8, 2025
CVE-2024-13186
7.5

The MinigameCenter module has insufficient URL loading restrictions, allowing attackers to load arbitrary URLs and potentially leak sensitive informat...

Jan 8, 2025
CVE-2024-13173
7.5

The health module in affected Vivo devices has insufficient URL loading restrictions, allowing attackers to access sensitive information. This vulnera...

Jan 8, 2025
CVE-2024-53623
7.5

This vulnerability allows attackers to bypass access controls in TP-Link Archer C7 v5 routers via the l_0_0.xml component, potentially exposing sensit...

Nov 29, 2024
CVE-2024-50589
7.5

This vulnerability allows an unauthenticated attacker on the same local network as a medical office to query an unprotected FHIR API, potentially expo...

Nov 8, 2024
CVE-2024-48953
7.5

This vulnerability allows unauthenticated attackers to register custom authentication plugins in Logpoint, bypassing normal authentication mechanisms....

Nov 7, 2024
CVE-2024-5749
7.5

This vulnerability in certain HP DesignJet printers allows attackers to view SMTP server credentials through credential reflection. Attackers could po...

Oct 15, 2024
CVE-2024-45276
7.5

CVE-2024-45276 allows unauthenticated remote attackers to read files from the /tmp directory due to missing authentication checks. This affects system...

Oct 15, 2024
CVE-2024-48791
7.5

This vulnerability in the Plug n Play Camera app allows remote attackers to access sensitive information through the firmware update process. Attacker...

Oct 14, 2024
CVE-2024-48768
7.5

This vulnerability in the Almando Control app allows remote attackers to access sensitive information through insecure firmware update mechanisms. Att...

Oct 11, 2024
CVE-2024-48771
7.5

This vulnerability in Almando Play APP allows remote attackers to access sensitive information during the firmware update process. The issue affects u...

Oct 11, 2024
CVE-2024-48774
7.5

This vulnerability in Fermax Asia Pacific's com.fermax.vida application version 2.4.6 allows remote attackers to access sensitive information through ...

Oct 11, 2024
CVE-2024-48776
7.5

A vulnerability in Shelly com.home.shelly 1.0.4 allows remote attackers to access sensitive information through the firmware update process. This affe...

Oct 11, 2024
CVE-2024-8751
7.5

An unauthenticated attacker can modify the IP address of MSC800 devices via Sopas ET protocol, causing denial of service by making devices unreachable...

Sep 12, 2024
CVE-2024-21183
7.5

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to access sensitive data. I...

Jul 16, 2024
CVE-2024-37767
7.5

This vulnerability allows attackers to access all user information in 14Finger v1.1 through insecure permissions in the /api/admin/user component. Att...

Jul 5, 2024
CVE-2024-1662
7.5

This vulnerability allows unauthenticated attackers to retrieve sensitive embedded data from the PowerBank Application due to missing authentication a...

Jun 5, 2024
CVE-2023-44413
7.5

This vulnerability allows remote attackers to cause denial-of-service on D-Link D-View systems by exploiting an unauthenticated shutdown_coreserver ac...

May 3, 2024
CVE-2024-21006
7.5

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to access sensitive data. I...

Apr 16, 2024
CVE-2022-48621
7.5

This CVE describes a missing authentication vulnerability in Huawei/HarmonyOS Wi-Fi modules that allows attackers to access critical functions without...

Feb 18, 2024
CVE-2023-49115
7.5

MachineSense devices use unauthenticated MQTT messaging for monitoring and remote viewing of sensor data, allowing attackers to intercept or manipulat...

Feb 1, 2024
CVE-2023-6942
7.5

This vulnerability allows remote unauthenticated attackers to bypass authentication in multiple Mitsubishi Electric industrial software products by se...

Jan 30, 2024
CVE-2023-40393
7.5

This vulnerability allows unauthorized access to photos in the Hidden Photos Album on Apple devices without proper authentication. It affects users of...

Jan 10, 2024
CVE-2023-6595
7.5

CVE-2023-6595 is an authentication bypass vulnerability in WhatsUp Gold network monitoring software. Unauthenticated attackers can access an API endpo...

Dec 14, 2023

About Missing Authentication (CWE-306)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Our database tracks 675 CVEs classified as CWE-306, with 325 rated critical and 243 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.5.

External reference: View CWE-306 on MITRE CWE →

Monitor Missing Authentication Vulnerabilities

Get alerted when new Missing Authentication CVEs affect your infrastructure.

Start Monitoring Free