CWE-306: Missing Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

658
Total CVEs
312
Critical
239
High
8.4
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
78
2025
257
2024
104
2023
84
2022
53

Top Affected Vendors

1 Oracle 21
2 Socomec 10
3 Q Free 10
4 Schneider Electric 9
5 Vasion 9
6 Microsoft 9
7 Sap 9
8 Siemens 9
9 Dlink 8
10 Idattend 7

All Missing Authentication CVEs (658)

CVE-2023-53968
9.8

This authentication bypass vulnerability in Screen SFT DAB 600/C firmware allows attackers to delete user accounts without credentials by exploiting I...

Dec 22, 2025
CVE-2023-53964
9.8

This vulnerability allows unauthenticated remote attackers to send a POST request to the /usr/cgi-bin/restorefactory.cgi endpoint to trigger a factory...

Dec 22, 2025
CVE-2025-12049
9.8

CVE-2025-12049 is a critical authentication bypass vulnerability in Sharp Display Solutions Media Player MP-01 that allows unauthenticated attackers t...

Dec 22, 2025
CVE-2025-63389
9.8

A critical authentication bypass vulnerability in Ollama platform allows remote attackers to perform unauthorized model management operations without ...

Dec 18, 2025
CVE-2025-43428
9.8

This CVE describes an authentication bypass vulnerability in Apple's Photos app where unauthorized users can view photos in the Hidden Photos Album wi...

Dec 17, 2025
CVE-2023-53771
9.8

MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication by se...

Dec 9, 2025
CVE-2023-53774
9.8

MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol, allowing attackers to send crafted commands via the svdrpsend.s...

Dec 9, 2025
CVE-2021-47731
9.8

Selea Targa IP OCR-ANPR cameras contain a hidden developer backdoor page accessible with hard-coded credentials 'Selea781830'. This allows attackers t...

Dec 9, 2025
CVE-2025-27019
9.8

This critical vulnerability in Infinera MTC-9's remote shell service allows unauthenticated attackers to gain full system access via reverse shells us...

Dec 8, 2025
CVE-2025-27020
9.8

An improper SSH configuration in Infinera MTC-9 allows unauthenticated attackers to execute arbitrary commands and access the file system. This affect...

Dec 8, 2025
CVE-2025-59695
9.8

This vulnerability allows users with root access to the operating system to modify firmware on the Chassis Management Board without authentication. Th...

Dec 2, 2025
CVE-2025-63206
9.8

An authentication bypass vulnerability in Dasan Switch DS2924 web interface allows attackers to gain escalated privileges by storing crafted cookies i...

Nov 19, 2025
CVE-2025-9312
9.8

A missing authentication enforcement vulnerability in WSO2 products allows unauthenticated access to System REST APIs and SOAP services when mutual TL...

Nov 18, 2025
CVE-2025-11007
9.8

The CE21 Suite WordPress plugin versions 2.2.1 to 2.3.1 contain an authentication bypass vulnerability that allows unauthenticated attackers to modify...

Nov 4, 2025
CVE-2025-12476
9.8

CVE-2025-12476 is a critical authentication bypass vulnerability affecting BLU-IC2 and BLU-IC4 devices. Attackers can access sensitive resources witho...

Oct 29, 2025
CVE-2025-12477
9.8

This vulnerability allows attackers to obtain server version information from BLU-IC2 and BLU-IC4 devices. This information disclosure can facilitate ...

Oct 29, 2025
CVE-2025-62481
9.8

An unauthenticated remote code execution vulnerability in Oracle Marketing (part of Oracle E-Business Suite) allows attackers to completely compromise...

Oct 21, 2025
CVE-2025-61757
KEV EPSS 82.2% 9.8

This critical vulnerability in Oracle Identity Manager allows unauthenticated attackers to remotely compromise the system via HTTP requests, leading t...

Oct 21, 2025
CVE-2025-53072
9.8

This critical vulnerability in Oracle Marketing allows unauthenticated attackers with network access via HTTP to completely compromise the Oracle Mark...

Oct 21, 2025
CVE-2025-53037
9.8

An unauthenticated remote code execution vulnerability in Oracle Financial Services Analytical Applications Infrastructure allows attackers to complet...

Oct 21, 2025
CVE-2025-62586
9.8

CVE-2025-62586 is a critical authentication bypass vulnerability in OPEXUS FOIAXpress that allows remote, unauthenticated attackers to reset administr...

Oct 16, 2025
CVE-2025-9152
9.8

This vulnerability allows unauthenticated attackers to generate administrative access tokens in WSO2 API Manager by exploiting missing authentication/...

Oct 16, 2025
CVE-2025-40765
9.8

An information disclosure vulnerability in TeleControl Server Basic V3.1 allows unauthenticated remote attackers to obtain password hashes and use the...

Oct 14, 2025
CVE-2025-59246
9.8

This critical vulnerability in Azure Entra ID (formerly Azure Active Directory) allows attackers to elevate privileges within cloud identity systems. ...

Oct 9, 2025
CVE-2025-35050
9.8

CVE-2025-35050 is a critical remote code execution vulnerability in Newforma Info Exchange (NIX) that allows unauthenticated attackers to execute arbi...

Oct 9, 2025
CVE-2025-34223
9.8

This vulnerability allows unauthenticated remote attackers to take over administrative control of Vasion Print (formerly PrinterLogic) systems during ...

Sep 29, 2025
CVE-2025-34216
9.8

Vasion Print (formerly PrinterLogic) Virtual Appliance exposes unauthenticated REST API endpoints that leak configuration files, clear-text passwords,...

Sep 29, 2025
CVE-2025-34221
9.8

This vulnerability allows unauthenticated attackers to access all internal Docker containers in Vasion Print (formerly PrinterLogic) deployments, bypa...

Sep 29, 2025
CVE-2025-34207
9.8

This vulnerability allows attackers to capture SSH private keys from compromised Docker containers in Vasion Print deployments due to insecure SSH cli...

Sep 29, 2025
CVE-2025-41715
9.8

This vulnerability exposes a web application's database without authentication, allowing unauthenticated remote attackers to directly access and poten...

Sep 24, 2025
CVE-2025-57432
9.8

Blackmagic Web Presenter version 3.3 exposes an unauthenticated Telnet service on port 9977, allowing remote attackers to manipulate stream settings a...

Sep 22, 2025
CVE-2025-9971
9.8

Planet Technology Industrial Cellular Gateways have a missing authentication vulnerability that allows unauthenticated remote attackers to manipulate ...

Sep 17, 2025
CVE-2025-10452
9.8

CVE-2025-10452 is a critical Missing Authentication vulnerability in Gotac's Statistical Database System that allows unauthenticated remote attackers ...

Sep 15, 2025
CVE-2025-58434
EPSS 11.2% 9.8

This vulnerability in Flowise allows unauthenticated attackers to generate password reset tokens for any user account, leading to complete account tak...

Sep 12, 2025
CVE-2025-54942
9.8

This vulnerability allows remote attackers to access deployment functionality in SUNNET Corporate Training Management System without authentication. A...

Aug 30, 2025
CVE-2025-8861
9.8

CVE-2025-8861 is a critical Missing Authentication vulnerability in TSA software developed by Changing. Unauthenticated remote attackers can directly ...

Aug 29, 2025
CVE-2025-53118
EPSS 25.2% 9.8

An authentication bypass vulnerability in Securden Unified PAM allows unauthenticated attackers to access administrator backup functions. This exposes...

Aug 25, 2025
CVE-2025-9254
9.8

CVE-2025-9254 is a critical authentication bypass vulnerability in WebITR software developed by Uniong. Unauthenticated remote attackers can exploit t...

Aug 22, 2025
CVE-2025-27214
9.8

A Missing Authentication for Critical Function vulnerability in UniFi Connect EV Station Pro allows attackers with physical or adjacent network access...

Aug 21, 2025
CVE-2025-51543
9.8

CVE-2025-51543 is an authentication bypass vulnerability in Cicool builder that allows unauthenticated attackers to reset the administrator password v...

Aug 19, 2025
CVE-2025-5095
9.8

CVE-2025-5095 is an authentication bypass vulnerability in Burk Technology ARC Solo devices that allows unauthenticated attackers to change passwords ...

Aug 8, 2025
CVE-2025-8284
9.8

CVE-2025-8284 is a critical authentication bypass vulnerability in Packet Power Monitoring and Control Web Interface that allows unauthenticated acces...

Aug 8, 2025
CVE-2025-6260
9.8

This vulnerability allows unauthenticated attackers to reset user credentials on affected thermostats by manipulating elements in the embedded web int...

Jul 24, 2025
CVE-2025-40736
9.8

This critical vulnerability in SINEC NMS allows unauthenticated attackers to reset the superadmin password through an exposed endpoint, granting them ...

Jul 8, 2025
CVE-2025-45814
9.8

Missing authentication checks in the query.fcgi endpoint of NovelSat NS3000 and NS2000 satellite modems allow attackers to hijack active sessions with...

Jul 2, 2025
CVE-2025-34069
9.8

This authentication bypass vulnerability in GFI Kerio Control allows unauthenticated attackers to gain full administrative access to the firewall appl...

Jul 2, 2025
CVE-2025-34071
9.8

This critical vulnerability in GFI Kerio Control allows attackers with administrative access to upload malicious firmware images and execute arbitrary...

Jul 2, 2025
CVE-2025-5310
9.8

Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented, unauthenticated target communication framework (TCF) interface on a speci...

Jun 27, 2025
CVE-2025-3699
9.8

CVE-2025-3699 is a critical authentication bypass vulnerability affecting multiple Mitsubishi Electric air conditioning control systems. Unauthenticat...

Jun 26, 2025
CVE-2025-1907
9.8

Instantel Micromate devices have an unauthenticated configuration port that allows attackers to execute arbitrary commands if they can connect to it. ...

May 30, 2025

About Missing Authentication (CWE-306)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Our database tracks 658 CVEs classified as CWE-306, with 312 rated critical and 239 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.4.

External reference: View CWE-306 on MITRE CWE →

Monitor Missing Authentication Vulnerabilities

Get alerted when new Missing Authentication CVEs affect your infrastructure.

Start Monitoring Free