CWE-306: Missing Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

678
Total CVEs
328
Critical
243
High
8.5
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
78
2025
257
2024
104
2023
84
2022
53

Top Affected Vendors

1 Oracle 21
2 Sap 11
3 Socomec 10
4 Siemens 10
5 Q Free 10
6 Schneider Electric 9
7 Microsoft 9
8 Vasion 9
9 Dlink 8
10 Mattermost 7

All Missing Authentication CVEs (678)

CVE-2023-6942
7.5

This vulnerability allows remote unauthenticated attackers to bypass authentication in multiple Mitsubishi Electric industrial software products by se...

Jan 30, 2024
CVE-2023-40393
7.5

This vulnerability allows unauthorized access to photos in the Hidden Photos Album on Apple devices without proper authentication. It affects users of...

Jan 10, 2024
CVE-2023-6595
7.5

CVE-2023-6595 is an authentication bypass vulnerability in WhatsUp Gold network monitoring software. Unauthenticated attackers can access an API endpo...

Dec 14, 2023
CVE-2023-46978
7.5

This vulnerability allows unauthenticated attackers to reset the admin login password and WiFi passwords on TOTOLINK X6000R routers. Attackers can gai...

Oct 31, 2023
CVE-2023-27257
7.5

This vulnerability allows unauthenticated attackers to retrieve student information from IDAttend's IDWeb application by exploiting missing authentica...

Oct 25, 2023
CVE-2023-27259
7.5

This vulnerability allows unauthenticated attackers to extract sensitive student and teacher data from IDAttend's IDWeb application. It affects organi...

Oct 25, 2023
CVE-2023-27376
7.5

This vulnerability allows unauthenticated attackers to extract sensitive student data from IDAttend's IDWeb application. It affects organizations usin...

Oct 25, 2023
CVE-2023-26570
7.5

This vulnerability allows unauthenticated attackers to extract sensitive student data from IDAttend's IDWeb application. It affects organizations usin...

Oct 25, 2023
CVE-2023-26574
7.5

CVE-2023-26574 allows unauthenticated attackers to extract sensitive student data from IDAttend's IDWeb application by exploiting missing authenticati...

Oct 25, 2023
CVE-2023-26576
7.5

This vulnerability allows unauthenticated attackers to extract sensitive student data from IDAttend's IDWeb application by exploiting missing authenti...

Oct 25, 2023
CVE-2023-26580
7.5

CVE-2023-26580 is an unauthenticated arbitrary file read vulnerability in IDAttend's IDWeb application version 3.1.013. This allows attackers without ...

Oct 25, 2023
CVE-2023-39981
7.5

MXsecurity versions before v1.0.1 have an authentication bypass vulnerability that allows remote attackers to access device information without proper...

Sep 2, 2023
CVE-2023-38030
7.5

Saho ADM100 and ADM-100FP attendance devices lack authentication for critical functions, allowing unauthenticated remote attackers to execute system c...

Aug 28, 2023
CVE-2023-38422
7.5

Walchem Intuition 9 firmware versions before v4.21 lack authentication on certain API routes, allowing unauthenticated attackers to access and export ...

Aug 23, 2023
CVE-2023-4334
7.5

The Broadcom RAID Controller Web server (nginx) exposes private files without requiring authentication. This vulnerability allows unauthorized users t...

Aug 15, 2023
CVE-2023-36347
7.5

CVE-2023-36347 is an authentication bypass vulnerability in POS Codekop v2.0 that allows unauthenticated attackers to access sensitive selling data th...

Jun 30, 2023
CVE-2023-31196
7.5

This vulnerability allows remote unauthenticated attackers to access sensitive information from affected Wi-Fi AP UNIT devices due to missing authenti...

Jun 13, 2023
CVE-2023-33247
7.5

CVE-2023-33247 is an unauthenticated remote code execution vulnerability in Talend Data Catalog's remote harvesting server. Attackers can deploy malic...

May 26, 2023
CVE-2023-0116
7.5

This CVE describes an authentication bypass vulnerability in Huawei's reminder module where broadcasts can be processed without proper authentication....

May 26, 2023
CVE-2023-23444
7.5

This vulnerability allows unauthenticated remote attackers to disrupt SICK Flexi Classic and Flexi Soft Gateways by changing their IP settings via bro...

May 12, 2023
CVE-2023-23906
7.5

This vulnerability allows remote unauthenticated attackers to execute critical functions on SkyBridge MB-A100/110 devices without authentication. Atta...

May 10, 2023
CVE-2023-31444
7.5

This vulnerability allows unauthenticated remote attackers to access the Jolokia endpoint in Talend Studio microservices, exposing the JVM via the JMX...

Apr 28, 2023
CVE-2023-29413
7.5

This vulnerability allows unauthenticated attackers to cause Denial-of-Service on Schneider UPS Monitor service by exploiting missing authentication f...

Apr 18, 2023
CVE-2023-21979
7.5

This vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via the T3 protocol to gain unauthorized access to s...

Apr 18, 2023
CVE-2023-27747
7.5

BlackVue DR750-2CH LTE dash cameras running firmware version 1.012_2022.10.26 lack authentication on their web server interface. This allows attackers...

Apr 13, 2023
CVE-2020-14140
7.5

CVE-2020-14140 is an unauthenticated API vulnerability in Xiaomi router firmware that allows attackers to retrieve WiFi passwords without authenticati...

Mar 29, 2023
CVE-2023-25570
7.5

This vulnerability in Apollo configuration management system allows unauthenticated access to the built-in Eureka service when apollo-configservice is...

Feb 20, 2023
CVE-2022-47703
7.5

The TIANJIE CPE906-3 device has a vulnerability that allows unauthenticated attackers to retrieve administrative passwords. This affects devices runni...

Feb 16, 2023
CVE-2022-24990
7.5

CVE-2022-24990 is an unauthenticated remote code execution vulnerability in TerraMaster NAS devices. Attackers can discover the administrative passwor...

Feb 7, 2023
CVE-2022-30313
7.5

Honeywell Experion PKS Safety Manager lacks authentication on proprietary protocols, allowing unauthenticated attackers to manipulate controller state...

Jul 28, 2022
CVE-2021-34538
7.5

This vulnerability in Apache Hive allows unauthorized users to manipulate existing User-Defined Functions (UDFs) without proper authorization checks. ...

Jul 16, 2022
CVE-2022-28771
7.5

CVE-2022-28771 is an authentication bypass vulnerability in SAP Business One License Service API that allows unauthenticated attackers to send malicio...

Jul 12, 2022
CVE-2022-21952
7.5

CVE-2022-21952 is a missing authentication vulnerability in SUSE Manager Server's spacewalk-java component that allows remote attackers to trigger dis...

Jun 22, 2022
CVE-2021-42893
7.5

CVE-2021-42893 is an information disclosure vulnerability in TOTOLINK EX1200T routers where attackers can access sensitive configuration data includin...

Jun 3, 2022
CVE-2021-42889
7.5

This vulnerability in TOTOLINK EX1200T routers allows unauthenticated attackers to retrieve sensitive WiFi configuration information including network...

Jun 3, 2022
CVE-2022-26026
7.5

CVE-2022-26026 is a denial-of-service vulnerability in Open Automation Software OAS Platform's SecureConfigValues functionality. Attackers can send sp...

May 25, 2022
CVE-2022-23345
7.5

BigAnt Server v5.6.06 contains an incorrect access control vulnerability that allows attackers to bypass authentication mechanisms. This affects organ...

Mar 21, 2022
CVE-2022-26267
7.5

Piwigo v12.2.0 contains an information disclosure vulnerability in the admin maintenance actions page. Attackers can exploit this to leak sensitive in...

Mar 18, 2022
CVE-2021-44262
7.5

This vulnerability allows remote attackers to access the 'MNU_top.htm' page on Netgear WAC104 access points without authentication, exposing sensitive...

Mar 17, 2022
CVE-2022-25508
7.5

An access control vulnerability in FreeTAKServer v1.9.8 allows unauthenticated attackers to create excessive routes, causing denial of service, or cre...

Mar 11, 2022
CVE-2021-38283
7.5

This vulnerability allows remote attackers to access sensitive log files in Wipro Holmes Orchestrator by exploiting a predictable /log URI. Attackers ...

Nov 29, 2021
CVE-2021-41104
7.5

ESPHome versions 2021.9.1 and older with web_server enabled and HTTP basic auth configured are vulnerable to authentication bypass. Attackers can perf...

Sep 28, 2021
CVE-2021-22012
7.5

CVE-2021-22012 is an information disclosure vulnerability in VMware vCenter Server's unauthenticated appliance management API. Attackers with network ...

Sep 23, 2021
CVE-2021-20474
7.5

IBM Guardium Data Encryption (GDE) versions 3.0.0.2 and 4.0.0.4 have an authentication bypass vulnerability where certain functionality requiring user...

Jul 7, 2021
CVE-2021-35941
7.5

This vulnerability allows unauthenticated attackers to trigger a factory reset on Western Digital My Book Live and My Book Live Duo network storage de...

Jun 29, 2021
CVE-2021-31793
7.5

This vulnerability allows unauthenticated attackers to access live snapshots and video streams from NightOwl WDB-20-V2 doorbell cameras. The device's ...

May 6, 2021
CVE-2020-35755
7.5

CVE-2020-35755 is an information disclosure vulnerability in Libre Wireless LS9 devices where the luci_service daemon on port 7777 allows unauthentica...

May 3, 2021
CVE-2021-20990
7.5

Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older expose an internal management service on port 8000 without authentication....

Apr 19, 2021
CVE-2021-28148
7.5

This vulnerability allows unauthenticated attackers to send unlimited requests to a specific Grafana Enterprise API endpoint, causing denial of servic...

Mar 22, 2021
CVE-2020-19419
7.5

This vulnerability allows remote attackers to access sensitive device information from the Emerson Smart Wireless Gateway 1420 administrator console w...

Mar 10, 2021

About Missing Authentication (CWE-306)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Our database tracks 678 CVEs classified as CWE-306, with 328 rated critical and 243 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.5.

External reference: View CWE-306 on MITRE CWE →

Monitor Missing Authentication Vulnerabilities

Get alerted when new Missing Authentication CVEs affect your infrastructure.

Start Monitoring Free