CWE-306: Missing Authentication

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

662
Total CVEs
316
Critical
239
High
8.4
Avg CVSS
6
In CISA KEV

Yearly Trend

2026
78
2025
257
2024
104
2023
84
2022
53

Top Affected Vendors

1 Oracle 21
2 Socomec 10
3 Q Free 10
4 Schneider Electric 9
5 Vasion 9
6 Microsoft 9
7 Sap 9
8 Siemens 9
9 Dlink 8
10 Idattend 7

All Missing Authentication CVEs (662)

CVE-2023-34060
9.8

This CVE describes an authentication bypass vulnerability in VMware Cloud Director Appliance 10.5 when upgraded from older versions. Attackers with ne...

Nov 14, 2023
CVE-2023-22069
9.8

This critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to completely comp...

Oct 17, 2023
CVE-2023-22072
9.8

This critical vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via T3 or IIOP protocols to completely comp...

Oct 17, 2023
CVE-2023-44116
9.8

This vulnerability in Huawei's APPWidget module allows apps to run without proper authorization due to insufficient permission verification. It affect...

Oct 11, 2023
CVE-2023-37483
9.8

SAP PowerDesigner 16.7 has an improper access control vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries against the...

Aug 8, 2023
CVE-2023-36669
9.8

CVE-2023-36669 is a critical authentication bypass vulnerability in Kratos NGC Indoor Units (IDU) that allows remote attackers to impersonate the Touc...

Jul 18, 2023
CVE-2023-35830
9.8

This critical vulnerability in STW TCG-4 and TCG-4lite connectivity modules allows unauthenticated attackers to gain full root access via SMS over LTE...

Jun 29, 2023
CVE-2023-35854
9.8

CVE-2023-35854 is an authentication bypass vulnerability in Zoho ManageEngine ADSelfService Plus that allows attackers to steal domain controller sess...

Jun 20, 2023
CVE-2023-27396
9.8

CVE-2023-27396 affects OMRON FINS protocol implementations, allowing attackers to intercept plaintext communications and inject arbitrary commands wit...

Jun 19, 2023
CVE-2020-36724
9.8

The Wordable WordPress plugin up to version 3.1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain admini...

Jun 7, 2023
CVE-2020-36713
9.8

The MStore API WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to create administrator accounts, del...

Jun 7, 2023
CVE-2023-2704
9.8

The BP Social Connect WordPress plugin versions up to 1.5 have an authentication bypass vulnerability that allows unauthenticated attackers to log in ...

May 19, 2023
CVE-2023-1096
9.8

CVE-2023-1096 is a critical authentication bypass vulnerability in NetApp SnapCenter that allows remote unauthenticated attackers to gain administrati...

May 12, 2023
CVE-2023-20126
9.8

An unauthenticated remote attacker can execute arbitrary code with full privileges on Cisco SPA112 2-Port Phone Adapters by exploiting a missing authe...

May 4, 2023
CVE-2023-28697
9.8

Moxa MiiNePort E1 devices have an insufficient access control vulnerability that allows unauthenticated remote attackers to perform arbitrary system o...

Apr 27, 2023
CVE-2023-2231
9.8

This critical vulnerability in MAXTECH MAX-G866ac routers allows remote attackers to access the remote management interface without authentication. At...

Apr 21, 2023
CVE-2023-29411
9.8

This vulnerability allows unauthenticated attackers to change administrative credentials via the Java RMI interface, potentially leading to remote cod...

Apr 18, 2023
CVE-2022-41331
9.8

CVE-2022-41331 allows remote unauthenticated attackers to access Redis and MongoDB databases in FortiPresence infrastructure servers. This affects org...

Apr 11, 2023
CVE-2022-36983
9.8

This critical authentication bypass vulnerability in Ivanti Avalanche allows remote attackers to gain unauthorized access without credentials. The fla...

Mar 29, 2023
CVE-2023-28326
9.8

This vulnerability allows attackers to elevate their privileges in any Apache OpenMeetings room, potentially gaining administrative control. It affect...

Mar 28, 2023
CVE-2023-1140
9.8

This vulnerability in Delta Electronics InfraSuite Device Master allows unauthenticated remote attackers to execute arbitrary code with administrator ...

Mar 27, 2023
CVE-2023-27060
9.8

LightCMS v1.3.7 contains a remote code execution vulnerability in the image:make function that allows attackers to execute arbitrary code on the serve...

Mar 22, 2023
CVE-2023-25589
9.8

An unauthenticated remote attacker can create arbitrary administrative users on ClearPass Policy Manager's web interface, leading to complete cluster ...

Mar 22, 2023
CVE-2022-45551
9.8

This vulnerability allows attackers to execute arbitrary WGET commands through the Network Diagnosis endpoint, leading to privilege escalation on affe...

Mar 3, 2023
CVE-2022-45138
9.8

CVE-2022-45138 is an authentication bypass vulnerability in the web-based management configuration backend, allowing unauthenticated attackers to read...

Feb 27, 2023
CVE-2022-45140
9.8

CVE-2022-45140 allows unauthenticated attackers to write arbitrary data with root privileges to the configuration backend storage. This can lead to re...

Feb 27, 2023
CVE-2023-23452
9.8

This critical vulnerability in SICK FX0-GPNT firmware allows unauthenticated remote attackers to execute arbitrary code by sending specially crafted R...

Feb 20, 2023
CVE-2022-42970
9.8

CVE-2022-42970 is a critical authentication bypass vulnerability in APC/Schneider Electric Easy UPS Online Monitoring Software that allows unauthentic...

Feb 1, 2023
CVE-2022-20857
9.8

CVE-2022-20857 is a critical vulnerability in Cisco Nexus Dashboard that allows unauthenticated remote attackers to execute arbitrary commands, read/u...

Jul 21, 2022
CVE-2022-20861
9.8

CVE-2022-20861 allows unauthenticated remote attackers to execute arbitrary commands, read/upload container images, or perform CSRF attacks on Cisco N...

Jul 21, 2022
CVE-2022-24562
9.8

CVE-2022-24562 allows unauthenticated attackers to send GET/POST requests to Airserv in IOBit IOTransfer, granting them full file-system read/write ac...

Jun 16, 2022
CVE-2021-41418
9.8

AriaNg versions 0.1.0 through 1.2.2 have an authentication bypass vulnerability that allows unauthenticated users to access the web interface and cont...

Jun 15, 2022
CVE-2022-30230
9.8

This vulnerability allows unauthenticated attackers to create administrative user accounts in SICAM GridEdge Classic systems. All versions before V2.6...

Jun 14, 2022
CVE-2022-28660
9.8

This vulnerability allows unauthenticated access to Grafana Enterprise Logs querier component when X-Scope-OrgID header is used, bypassing authenticat...

May 20, 2022
CVE-2022-1388
9.8

CVE-2022-1388 is an authentication bypass vulnerability in F5 BIG-IP's iControl REST API that allows unauthenticated attackers to execute arbitrary sy...

May 5, 2022
CVE-2022-1300
9.8

Multiple TRUMPF TruTops products expose an unauthenticated service function that allows attackers to execute unauthorized actions. This vulnerability ...

May 2, 2022
CVE-2022-28719
9.8

CVE-2022-28719 is a critical authentication bypass vulnerability in AssetView management software that allows unauthenticated remote attackers to uplo...

Apr 28, 2022
CVE-2022-0992
9.8

The SiteGround Security plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log in as administrat...

Apr 19, 2022
CVE-2021-46009
9.8

This vulnerability allows unauthenticated attackers to access sensitive pages and modify admin configurations on Totolink A3100R routers. It affects a...

Mar 30, 2022
CVE-2022-26501
9.8

CVE-2022-26501 is an incorrect access control vulnerability in Veeam Backup & Replication that allows unauthenticated attackers to execute arbitrary c...

Mar 17, 2022
CVE-2021-44259
9.8

This vulnerability allows remote attackers to access the 'wx.html' page on WAVLINK AC1200 routers without authentication, granting them friend-level a...

Mar 17, 2022
CVE-2022-25251
9.8

CVE-2022-25251 is an authentication bypass vulnerability in Axeda agent and Desktop Server for Windows that allows remote unauthenticated attackers to...

Mar 16, 2022
CVE-2021-46384
9.8

MCMS versions up to 5.2.5 contain a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary ...

Mar 4, 2022
CVE-2021-35587
9.8

This critical vulnerability in Oracle Access Manager allows unauthenticated attackers to remotely compromise the system via HTTP requests, potentially...

Jan 19, 2022
CVE-2022-23227
9.8

This critical vulnerability in NUUO NVRmini2 network video recorders allows unauthenticated attackers to upload encrypted TAR archives to add arbitrar...

Jan 14, 2022
CVE-2021-20158
9.8

This vulnerability allows unauthenticated attackers to change the administrator password on Trendnet AC2600 TEW-827DRU routers. Attackers can exploit ...

Dec 30, 2021
CVE-2021-45232
9.8

This vulnerability allows attackers to bypass authentication in Apache APISIX Dashboard by directly accessing APIs through the gin framework interface...

Dec 27, 2021
CVE-2021-44077
9.8

CVE-2021-44077 is an unauthenticated remote code execution vulnerability in Zoho ManageEngine products. Attackers can exploit this via specific REST A...

Nov 29, 2021
CVE-2021-42783
9.8

This vulnerability allows unauthenticated attackers to execute administrative actions on D-Link DWR-932C E1 routers by exploiting a missing authentica...

Nov 23, 2021
CVE-2021-20136
9.8

CVE-2021-20136 is an unauthenticated remote code execution vulnerability in ManageEngine Log360. Attackers can overwrite the database configuration to...

Nov 1, 2021

About Missing Authentication (CWE-306)

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Our database tracks 662 CVEs classified as CWE-306, with 316 rated critical and 239 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.4.

External reference: View CWE-306 on MITRE CWE →

Monitor Missing Authentication Vulnerabilities

Get alerted when new Missing Authentication CVEs affect your infrastructure.

Start Monitoring Free