CWE-306: Missing Authentication
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Yearly Trend
Top Affected Vendors
All Missing Authentication CVEs (675)
An unauthenticated denial-of-service vulnerability in Socomec DIRIS Digiware M-70 allows attackers to crash the device by sending a specially crafted ...
Dec 1, 2025AudioCodes Fax Server and Auto-Attendant IVR appliances contain an unauthenticated file read vulnerability in the download.php script. Attackers can r...
Nov 19, 2025This vulnerability allows unauthenticated attackers with network access via HTTP to cause a denial-of-service (DoS) condition in Oracle Financial Serv...
Oct 21, 2025An unauthenticated remote attacker can exploit this vulnerability in Oracle WebLogic Server via HTTP/2 to cause a denial of service, resulting in serv...
Oct 21, 2025An unauthenticated remote attacker can send a Modbus command to turn off the output of an Uninterruptible Power Supply (UPS), causing a denial of serv...
Oct 14, 2025The Chaos Controller Manager in Chaos Mesh exposes an unauthenticated GraphQL debugging server that allows attackers to kill arbitrary processes in an...
Sep 15, 2025A cryptographic implementation flaw in FactoryTalk Activation Manager allows attackers to decrypt network traffic. This vulnerability affects all syst...
Sep 9, 2025The SecGate3600 firewall has an authentication bypass vulnerability in its user management endpoint that allows unauthenticated attackers to retrieve ...
Aug 27, 2025This vulnerability allows unauthenticated remote attackers to access measurement data stored on affected devices without any password protection. It a...
Aug 19, 2025This vulnerability allows unauthenticated API calls to trigger resource-intensive evaluations in Hydra, potentially causing denial of service attacks....
Aug 12, 2025This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to access sensitive data. I...
Jul 15, 2025This vulnerability allows unauthorized attackers to bypass security features in Windows Remote Desktop Licensing Service by exploiting missing authent...
Jul 8, 2025This vulnerability allows unauthorized remote attackers to trigger a fail-safe state on affected systems without authentication. Any system running th...
Jun 30, 2025This vulnerability allows remote attackers to access sensitive information from Autel MaxiCharger AC Wallbox Commercial charging stations without auth...
Jun 25, 2025CyberData 011209 Intercom has an authentication bypass vulnerability that allows unauthenticated attackers to access restricted features. This could l...
Jun 9, 2025This vulnerability allows remote attackers to bypass authentication in Soar Cloud HRD Human Resource Management System client applications. Attackers ...
Jun 6, 2025Missing authentication vulnerability in Wi-Fi AP UNIT 'AC-WPS-11ac series' allows remote unauthenticated attackers to access product configuration inf...
Apr 9, 2025Mattermost fails to enforce multi-factor authentication (MFA) on plugin endpoints, allowing authenticated attackers to bypass MFA protections via API ...
Mar 21, 2025This vulnerability allows unauthenticated attackers to access the /setup-complete API endpoint in Anything-LLM version 1.5.5, exposing sensitive syste...
Mar 20, 2025This vulnerability allows remote attackers to obtain administrator credentials in Synology Drive Server due to missing authentication for a critical w...
Mar 19, 2025This vulnerability allows unauthorized remote access to video footage and live streams from IROAD v9 dashcams. Attackers who gain initial access throu...
Mar 18, 2025An unauthenticated remote attacker can disable authentication profile servers in Q-Free MaxTime traffic management systems by sending crafted HTTP req...
Feb 12, 2025This vulnerability allows unauthenticated remote attackers to enable front panel authentication on Q-Free MaxTime systems via crafted HTTP requests. I...
Feb 12, 2025An unauthenticated remote attacker can disable front panel authentication in Q-Free MaxTime systems via crafted HTTP requests. This affects all Q-Free...
Feb 12, 2025This vulnerability allows unauthenticated remote attackers to enable authentication profile servers in Q-Free MaxTime traffic management systems via c...
Feb 12, 2025A missing authentication vulnerability in multiple NEC Aterm router models allows attackers to retrieve Wi-Fi passwords without authentication. This a...
Jan 15, 2025The MinigameCenter module has insufficient URL loading restrictions, allowing attackers to load arbitrary URLs and potentially leak sensitive informat...
Jan 8, 2025The MinigameCenter module has insufficient URL loading restrictions, allowing attackers to load arbitrary URLs and potentially leak sensitive informat...
Jan 8, 2025The health module in affected Vivo devices has insufficient URL loading restrictions, allowing attackers to access sensitive information. This vulnera...
Jan 8, 2025This vulnerability allows attackers to bypass access controls in TP-Link Archer C7 v5 routers via the l_0_0.xml component, potentially exposing sensit...
Nov 29, 2024This vulnerability allows an unauthenticated attacker on the same local network as a medical office to query an unprotected FHIR API, potentially expo...
Nov 8, 2024This vulnerability allows unauthenticated attackers to register custom authentication plugins in Logpoint, bypassing normal authentication mechanisms....
Nov 7, 2024This vulnerability in certain HP DesignJet printers allows attackers to view SMTP server credentials through credential reflection. Attackers could po...
Oct 15, 2024CVE-2024-45276 allows unauthenticated remote attackers to read files from the /tmp directory due to missing authentication checks. This affects system...
Oct 15, 2024This vulnerability in the Plug n Play Camera app allows remote attackers to access sensitive information through the firmware update process. Attacker...
Oct 14, 2024This vulnerability in the Almando Control app allows remote attackers to access sensitive information through insecure firmware update mechanisms. Att...
Oct 11, 2024This vulnerability in Almando Play APP allows remote attackers to access sensitive information during the firmware update process. The issue affects u...
Oct 11, 2024This vulnerability in Fermax Asia Pacific's com.fermax.vida application version 2.4.6 allows remote attackers to access sensitive information through ...
Oct 11, 2024A vulnerability in Shelly com.home.shelly 1.0.4 allows remote attackers to access sensitive information through the firmware update process. This affe...
Oct 11, 2024An unauthenticated attacker can modify the IP address of MSC800 devices via Sopas ET protocol, causing denial of service by making devices unreachable...
Sep 12, 2024This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to access sensitive data. I...
Jul 16, 2024This vulnerability allows attackers to access all user information in 14Finger v1.1 through insecure permissions in the /api/admin/user component. Att...
Jul 5, 2024This vulnerability allows unauthenticated attackers to retrieve sensitive embedded data from the PowerBank Application due to missing authentication a...
Jun 5, 2024This vulnerability allows remote attackers to cause denial-of-service on D-Link D-View systems by exploiting an unauthenticated shutdown_coreserver ac...
May 3, 2024This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to access sensitive data. I...
Apr 16, 2024This CVE describes a missing authentication vulnerability in Huawei/HarmonyOS Wi-Fi modules that allows attackers to access critical functions without...
Feb 18, 2024MachineSense devices use unauthenticated MQTT messaging for monitoring and remote viewing of sensor data, allowing attackers to intercept or manipulat...
Feb 1, 2024This vulnerability allows remote unauthenticated attackers to bypass authentication in multiple Mitsubishi Electric industrial software products by se...
Jan 30, 2024This vulnerability allows unauthorized access to photos in the Hidden Photos Album on Apple devices without proper authentication. It affects users of...
Jan 10, 2024CVE-2023-6595 is an authentication bypass vulnerability in WhatsUp Gold network monitoring software. Unauthenticated attackers can access an API endpo...
Dec 14, 2023About Missing Authentication (CWE-306)
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Our database tracks 675 CVEs classified as CWE-306, with 325 rated critical and 243 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.5.
External reference: View CWE-306 on MITRE CWE →
Monitor Missing Authentication Vulnerabilities
Get alerted when new Missing Authentication CVEs affect your infrastructure.
Start Monitoring Free