CWE-306: Missing Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

687
Total CVEs
335
Critical
245
High
8.5
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
78
2025
257
2024
104
2023
84
2022
53

Top Affected Vendors

1 Oracle 22
2 Sap 12
3 Siemens 11
4 Socomec 10
5 Q Free 10
6 Schneider Electric 9
7 Microsoft 9
8 Apache 9
9 Vasion 9
10 Dlink 8

All Missing Authentication CVEs (687)

CVE-2023-41186
6.5

This vulnerability allows network-adjacent attackers to access D-Link DAP-1325 router functionality without authentication via the CGI interface. Atta...

May 3, 2024
CVE-2023-27357
6.5

This vulnerability allows network-adjacent attackers to access sensitive information from NETGEAR RAX30 routers without authentication. The flaw exist...

May 3, 2024
CVE-2022-48291
6.5

This CVE describes an authentication bypass vulnerability in the Bluetooth pairing process of Huawei devices. Attackers within Bluetooth range can pot...

Mar 27, 2023
CVE-2024-39364
6.3

The Advantech ADAM-5630 industrial controller has unauthenticated HTTP commands that allow remote attackers to restart the operating system, reboot ha...

Sep 27, 2024
CVE-2025-7706
6.1

CVE-2025-7706 is a missing authentication vulnerability in TUBITAK BILGEM Liderahenk software that allows remote attackers to execute code without pro...

Feb 17, 2026
CVE-2025-69285
6.1

SQLBot versions before 1.5.0 have an authentication bypass vulnerability in the /api/v1/datasource/uploadExcel endpoint. Unauthenticated attackers can...

Jan 21, 2026
CVE-2025-62287
6.1

This vulnerability in Oracle Life Sciences InForm allows unauthenticated attackers to modify or read limited data by tricking users into interacting w...

Oct 21, 2025
CVE-2025-12436
5.9

A policy bypass vulnerability in Google Chrome extensions allows malicious extensions to access sensitive information from browser process memory. Thi...

Nov 10, 2025
CVE-2025-42885
5.8

CVE-2025-42885 is an authentication bypass vulnerability in SAP HANA 2.0's hdbrss component that allows unauthenticated attackers to call remote-enabl...

Nov 11, 2025
CVE-2025-34229
5.8

This CVE describes a blind server-side request forgery (SSRF) vulnerability in Vasion Print (formerly PrinterLogic) that allows unauthenticated attack...

Sep 29, 2025
CVE-2025-34230
5.8

This CVE describes a blind server-side request forgery (SSRF) vulnerability in Vasion Print (formerly PrinterLogic) that allows unauthenticated attack...

Sep 29, 2025
CVE-2025-12941
5.7

This vulnerability allows authenticated local WiFi users to cause a denial of service by rebooting NETGEAR C6220 and C6230 cable modem/router devices....

Dec 9, 2025
CVE-2024-45355
5.5

This vulnerability allows attackers to bypass authorization controls in Xiaomi phone frameworks, enabling unauthorized access to sensitive methods. It...

Mar 27, 2025
CVE-2025-55073
5.4

This vulnerability allows attackers to edit arbitrary posts in Mattermost by exploiting an improper validation flaw in the MSTeams plugin OAuth flow. ...

Nov 14, 2025
CVE-2025-8558
5.4

CVE-2025-8558 is an authentication bypass vulnerability in Proofpoint Insider Threat Management Server that allows unauthenticated users on adjacent n...

Nov 3, 2025
CVE-2025-48742
5.4

This vulnerability in SIGB PMB installer allows remote attackers to execute arbitrary code on affected systems. It affects all systems running PMB ver...

May 27, 2025
CVE-2025-24271
5.4

This vulnerability allows an unauthenticated attacker on the same local network to send AirPlay commands to a signed-in Mac without requiring pairing....

Apr 29, 2025
CVE-2023-37325
5.4

This vulnerability allows network-adjacent attackers to modify wireless network settings on D-Link DAP-2622 routers without authentication. Attackers ...

May 7, 2024
CVE-2025-14294
5.3

The Razorpay for WooCommerce WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to modify billing and s...

Feb 19, 2026
CVE-2026-25878
5.3

CVE-2026-25878 is an authentication bypass vulnerability in the FroshAdminer plugin for Shopware Platform. Unauthenticated users can access the Admine...

Feb 9, 2026
CVE-2026-1332
5.3

MeetingHub software from HAMASTAR Technology has a missing authentication vulnerability that allows unauthenticated remote attackers to access specifi...

Jan 22, 2026
CVE-2026-0942
5.3

This vulnerability allows unauthenticated attackers to delete payment metadata logs from all WooCommerce orders using the Rede ItaΓΊ plugin. Any WordP...

Jan 16, 2026
CVE-2024-58336
5.3

Akuvox Smart Intercom S539 devices contain an unauthenticated vulnerability that allows remote attackers to access live video streams without authenti...

Dec 30, 2025
CVE-2025-63390
5.3

An authentication bypass vulnerability in AnythingLLM v1.8.5 allows unauthenticated attackers to enumerate and retrieve detailed information about all...

Dec 18, 2025
CVE-2025-12348
5.3

This vulnerability allows unauthenticated attackers to execute scheduled actions in the Icegram Express WordPress plugin by guessing action IDs. This ...

Dec 12, 2025
CVE-2023-53773
5.3

MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attackers to generate and retrieve live TV st...

Dec 9, 2025
CVE-2021-47727
5.3

Selea Targa IP OCR-ANPR cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without authenticat...

Dec 9, 2025
CVE-2025-11771
5.3

This vulnerability allows unauthenticated attackers to manipulate presale counters in WordPress sites using the TokenICO plugin. Attackers can modify ...

Nov 21, 2025
CVE-2025-12349
5.3

The Icegram Express WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to trigger immediate email sendin...

Nov 19, 2025
CVE-2023-7328
5.3

This vulnerability allows unauthenticated attackers to retrieve user data from Screen SFT DAB 600/C devices via the user management API. It exposes ac...

Nov 14, 2025
CVE-2025-11986
5.3

The Crypto WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to set a site-wide authentication state f...

Nov 11, 2025
CVE-2025-62607
5.3

An information disclosure vulnerability in Nautobot SSoT app versions before 3.10.0 allows unauthenticated attackers to view the ServiceNow public ins...

Oct 22, 2025
CVE-2025-0275
5.3

HCL BigFix Mobile versions 3.3 and earlier have an improper access control vulnerability that allows unauthorized users to access a limited set of end...

Oct 16, 2025
CVE-2025-0274
5.3

CVE-2025-0274 is an improper access control vulnerability in HCL BigFix Modern Client Management (MCM) that allows unauthorized users to access a limi...

Oct 16, 2025
CVE-2025-11671
5.3

Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability (CWE-306) that allows unauthenticated remote attack...

Oct 13, 2025
CVE-2025-11672
5.3

Uniweb/SoliPACS WebServer developed by EBM Technologies has a missing authentication vulnerability that allows unauthenticated remote attackers to acc...

Oct 13, 2025
CVE-2025-11171
5.3

The Chartify WordPress plugin has a critical authentication bypass vulnerability that allows unauthenticated attackers to execute administrative funct...

Oct 8, 2025
CVE-2025-42926
5.3

SAP NetWeaver Application Server Java has an authentication bypass vulnerability that allows unauthenticated attackers to access internal files. This ...

Sep 9, 2025
CVE-2025-7031
5.3

This vulnerability allows unauthenticated attackers to access configuration pages in Drupal that should require authentication. It affects Drupal site...

Jul 8, 2025
CVE-2025-6920
5.3

CVE-2025-6920 is an authentication bypass vulnerability in ai-inference-server's model inference API. The POST /invocations endpoint fails to validate...

Jul 1, 2025
CVE-2025-32782
5.3

Ash Authentication's account confirmation flow uses GET requests triggered by email links. Email clients and security tools may automatically follow t...

Apr 15, 2025
CVE-2024-52285
5.3

This vulnerability allows unauthenticated remote attackers to access sensitive data through exposed MQTT URLs without authentication in SiPass integra...

Mar 11, 2025
CVE-2024-37303
5.3

Synapse Matrix homeserver versions before 1.106 allow unauthenticated remote users to trigger downloads of remote media content and cache it locally, ...

Dec 3, 2024
CVE-2024-47865
5.3

A missing authentication vulnerability in Rakuten Turbo 5G firmware allows remote unauthenticated attackers to update or downgrade device firmware. Th...

Nov 20, 2024
CVE-2024-26011
5.3

This vulnerability allows unauthenticated attackers to execute arbitrary code or commands on affected Fortinet devices by sending specially crafted pa...

Nov 12, 2024
CVE-2024-8320
5.3

This vulnerability allows remote unauthenticated attackers to spoof the Network Isolation status of managed devices in Ivanti EPM. Attackers can make ...

Sep 10, 2024
CVE-2024-43272
5.3

This vulnerability allows unauthenticated attackers to view unpublished campaigns in the Icegram Engage WordPress plugin. It affects all WordPress sit...

Aug 19, 2024
CVE-2023-28470
5.3

Couchbase Server versions 5 through 7.1.3 expose the nsstats endpoint without requiring authentication. This allows unauthenticated attackers to acces...

Mar 23, 2023
CVE-2025-44039
5.1

This vulnerability allows local attackers with physical access to connect to the router's UART console via serial connection without authentication. A...

May 13, 2025
CVE-2025-60251
5.0

This vulnerability allows authentication bypass on Unitree Go2, G1, H1, and B2 robots by accepting any handshake secret containing the substring 'unit...

Sep 26, 2025

About Missing Authentication (CWE-306)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Our database tracks 687 CVEs classified as CWE-306, with 335 rated critical and 245 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.5.

External reference: View CWE-306 on MITRE CWE →

Monitor Missing Authentication Vulnerabilities

Get alerted when new Missing Authentication CVEs affect your infrastructure.

Start Monitoring Free