CWE-306: Missing Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

660
Total CVEs
314
Critical
239
High
8.4
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
78
2025
257
2024
104
2023
84
2022
53

Top Affected Vendors

1 Oracle 21
2 Socomec 10
3 Q Free 10
4 Schneider Electric 9
5 Vasion 9
6 Microsoft 9
7 Sap 9
8 Siemens 9
9 Dlink 8
10 Idattend 7

All Missing Authentication CVEs (660)

CVE-2025-22252
9.8

This vulnerability allows attackers who know an existing admin account name to bypass authentication and gain full administrative access to affected F...

May 28, 2025
CVE-2025-41651
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected devices due to missing authentication on...

May 27, 2025
CVE-2025-4555
9.8

The Okcat Parking Management Platform web management interface lacks authentication controls, allowing unauthenticated remote attackers to directly ac...

May 12, 2025
CVE-2025-46275
9.8

This critical vulnerability allows unauthenticated attackers to create administrator accounts on affected WGS network devices without any credentials....

Apr 24, 2025
CVE-2025-30727
9.8

This critical vulnerability in Oracle E-Business Suite's iSurvey Module allows unauthenticated attackers to remotely execute arbitrary code and comple...

Apr 15, 2025
CVE-2025-2567
9.8

This critical vulnerability allows attackers to modify or disable settings in Automated Tank Gauging (ATG) systems, disrupting fuel monitoring and sup...

Apr 15, 2025
CVE-2025-3248
KEV EPSS 92% 9.8

CVE-2025-3248 is an unauthenticated remote code execution vulnerability in Langflow's /api/v1/validate/code endpoint. Attackers can send crafted HTTP ...

Apr 7, 2025
CVE-2024-8196
9.8

The Anything-LLM desktop application for Windows opens port 3001 on all network interfaces (0.0.0.0) without authentication by default. This allows at...

Mar 20, 2025
CVE-2025-27647
9.8

This critical vulnerability in Vasion Print (formerly PrinterLogic) allows unauthenticated attackers to create partial admin user accounts. Affected o...

Mar 5, 2025
CVE-2025-27642
9.8

This vulnerability allows unauthenticated attackers to edit driver packages in Vasion Print (formerly PrinterLogic) systems. Attackers can upload mali...

Mar 5, 2025
CVE-2025-0896
9.8

Orthanc server versions before 1.5.8 have remote access enabled without basic authentication by default, allowing attackers to access medical imaging ...

Feb 13, 2025
CVE-2025-26359
9.8

This vulnerability allows unauthenticated remote attackers to reset user PINs in Q-Free MaxTime systems via crafted HTTP requests. It affects all Q-Fr...

Feb 12, 2025
CVE-2025-26344
9.8

This vulnerability allows unauthenticated remote attackers to enable passwordless guest mode in Q-Free MaxTime systems via crafted HTTP requests. It a...

Feb 12, 2025
CVE-2025-26347
9.8

This vulnerability allows unauthenticated remote attackers to edit user permissions in Q-Free MaxTime traffic management systems via crafted HTTP requ...

Feb 12, 2025
CVE-2025-26339
9.8

This vulnerability allows unauthenticated remote attackers to send crafted HTTP requests to Q-Free MaxTime traffic management systems, potentially com...

Feb 12, 2025
CVE-2025-26341
9.8

This vulnerability allows unauthenticated remote attackers to reset arbitrary user passwords in Q-Free MaxTime systems via crafted HTTP requests. It a...

Feb 12, 2025
CVE-2025-21535
9.8

CVE-2025-21535 is a critical vulnerability in Oracle WebLogic Server that allows unauthenticated attackers to remotely execute arbitrary code and comp...

Jan 21, 2025
CVE-2025-21524
9.8

This critical vulnerability in Oracle JD Edwards EnterpriseOne Tools allows unauthenticated attackers with network access via HTTP to completely compr...

Jan 21, 2025
CVE-2024-54983
9.8

This vulnerability allows attackers to bypass authentication on Quectel BC95-CNV cellular modules by sending specially crafted NAS (Non-Access Stratum...

Dec 19, 2024
CVE-2024-11680
9.8

CVE-2024-11680 is an authentication bypass vulnerability in ProjectSend file sharing software. Unauthenticated attackers can modify application config...

Nov 26, 2024
CVE-2024-47138
9.8

This vulnerability exposes an administrative interface on all network interfaces without authentication, allowing unauthenticated remote attackers to ...

Nov 22, 2024
CVE-2024-38643
9.8

This critical vulnerability in QNAP Notes Station 3 allows remote attackers to bypass authentication and execute privileged functions without credenti...

Nov 22, 2024
CVE-2024-21855
9.8

CVE-2024-21855 is an unauthenticated remote code execution vulnerability in GoCast 1.1.3's HTTP API. Attackers can send specially crafted HTTP request...

Nov 21, 2024
CVE-2024-0012
9.8

An authentication bypass vulnerability in Palo Alto Networks PAN-OS software allows unauthenticated attackers with network access to the management we...

Nov 18, 2024
CVE-2024-40404
9.8

This vulnerability allows attackers to bypass access controls in Cybele Software Thinfinity Workspace's WebSocket API endpoint, potentially enabling u...

Nov 13, 2024
CVE-2024-10386
9.8

CVE-2024-10386 is a critical authentication vulnerability in Rockwell Automation products that allows unauthenticated attackers with network access to...

Oct 25, 2024
CVE-2024-47575
9.8

This critical vulnerability in FortiManager allows unauthenticated attackers to execute arbitrary code or commands via specially crafted requests. It ...

Oct 23, 2024
CVE-2024-45274
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected devices via UDP packets...

Oct 15, 2024
CVE-2024-9984
9.8

CVE-2024-9984 is an authentication bypass vulnerability in Ragic Enterprise Cloud Database that allows unauthenticated remote attackers to steal any u...

Oct 15, 2024
CVE-2024-8456
9.8

This critical vulnerability allows unauthenticated remote attackers to download and upload firmware and system configurations on affected PLANET Techn...

Sep 30, 2024
CVE-2024-8310
9.8

CVE-2024-8310 is an authentication bypass vulnerability in OPW Fuel Management Systems SiteSentinel that allows attackers to gain full administrative ...

Sep 27, 2024
CVE-2024-7015
9.8

CVE-2024-7015 is a critical authentication bypass vulnerability in Profelis Informatics and Consulting PassBox that allows attackers to access sensiti...

Sep 9, 2024
CVE-2024-8584
9.8

Orca HCM from LEARNING DIGITAL has a critical missing authentication vulnerability that allows unauthenticated remote attackers to create administrato...

Sep 9, 2024
CVE-2024-4428
9.8

This CVE describes a critical authentication and authorization bypass vulnerability in Menulux Information Technologies Management Portal that allows ...

Aug 29, 2024
CVE-2024-36445
9.8

CVE-2024-36445 allows remote attackers to gain root shell access on Swissphone DiCal-RED 4009 devices via unauthenticated TELNET. This affects organiz...

Aug 22, 2024
CVE-2024-42462
9.8

CVE-2024-42462 is an authentication bypass vulnerability in upKeeper Manager that allows attackers to circumvent multi-factor authentication. This aff...

Aug 16, 2024
CVE-2024-5910
9.8

CVE-2024-5910 is a critical authentication bypass vulnerability in Palo Alto Networks Expedition that allows unauthenticated attackers with network ac...

Jul 10, 2024
CVE-2024-6422
9.8

CVE-2024-6422 allows unauthenticated remote attackers to manipulate devices via Telnet, enabling them to stop processes, read, delete, and modify data...

Jul 10, 2024
CVE-2024-32735
9.8

This vulnerability allows unauthenticated remote attackers to access PDNU REST APIs in CyberPower PowerPanel Enterprise, potentially leading to applic...

May 14, 2024
CVE-2023-42121
9.8

CVE-2023-42121 is a critical authentication bypass vulnerability in Control Web Panel that allows remote attackers to execute arbitrary code without a...

May 3, 2024
CVE-2023-39457
9.8

This critical vulnerability in Triangle MicroWorks SCADA Data Gateway allows remote attackers to bypass authentication completely and execute arbitrar...

May 3, 2024
CVE-2024-21014
9.8

This critical vulnerability in Oracle Hospitality Simphony allows unauthenticated attackers with network access via HTTP to completely compromise the ...

Apr 16, 2024
CVE-2024-3701
9.8

This vulnerability allows attackers to bypass authentication in the com.transsion.kolun.aiservice system application on Tecno/Infinix devices. Attacke...

Apr 15, 2024
CVE-2024-3777
9.8

CVE-2024-3777 is a critical authentication bypass vulnerability in Ai3 QbiBot's password reset feature. Unauthenticated remote attackers can reset any...

Apr 15, 2024
CVE-2023-1083
9.8

CVE-2023-1083 allows unauthenticated remote attackers to send and receive MQTT messages on vulnerable systems, enabling them to execute configuration ...

Apr 9, 2024
CVE-2024-2921
9.8

This vulnerability allows authenticated users with PAM access in Devolutions Server to bypass permission controls and view unauthorized PAM entries. I...

Mar 26, 2024
CVE-2023-5716
9.8

CVE-2023-5716 is a critical vulnerability in ASUS Armoury Crate software that allows remote attackers to write arbitrary files to the system without a...

Jan 19, 2024
CVE-2023-49255
9.8

This vulnerability allows unauthenticated attackers to execute commands with administrative privileges on affected routers by exploiting shared sessio...

Jan 12, 2024
CVE-2023-29485
9.8

This vulnerability in Heimdal Thor agent allows attackers to bypass network filtering, execute arbitrary code, and obtain sensitive information throug...

Dec 21, 2023
CVE-2023-49693
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on NETGEAR ProSAFE Network Management System devices by exploitin...

Nov 29, 2023

About Missing Authentication (CWE-306)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Our database tracks 660 CVEs classified as CWE-306, with 314 rated critical and 239 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.4.

External reference: View CWE-306 on MITRE CWE →

Monitor Missing Authentication Vulnerabilities

Get alerted when new Missing Authentication CVEs affect your infrastructure.

Start Monitoring Free