CWE-306: Missing Authentication
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Yearly Trend
Top Affected Vendors
All Missing Authentication CVEs (675)
This vulnerability allows unauthenticated remote attackers to gain root access to affected Hero Qubo HCD01_02 devices via TELNET. The devices have TEL...
Jul 4, 2023This vulnerability allows unauthenticated attackers to create malicious report files in IGSS project directories via the Data Server TCP interface. Wh...
Mar 21, 2023CVE-2022-32251 is an authentication bypass vulnerability in Siemens SINEMA Remote Connect Server that allows attackers to modify user permissions with...
Jun 14, 2022The Dr Trust USA iCheck Connect BP Monitor version 1.2.1 lacks proper authentication mechanisms, allowing unauthorized access to device functions and ...
Apr 7, 2022CVE-2021-33008 is an authentication bypass vulnerability in AVEVA System Platform versions 2017 through 2020 R2 P01. It allows unauthenticated attacke...
Apr 4, 2022This CVE describes a missing authentication mechanism in totolink EX300_v2 and EX1200T routers, allowing attackers to access administrative functions ...
Mar 30, 2022This vulnerability allows attackers on the local network to bypass password protection on Bosch AMC2 device configuration tools, enabling unauthorized...
Jan 19, 2022This vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges on NETGEAR R7800 routers. The flaw exists in...
Mar 5, 2021This vulnerability in HTCondor allows authenticated users to submit jobs as other users on the system due to a flaw in the IDTOKENS authentication met...
Jan 27, 2021The NVIDIA Delegated Licensing Service vulnerability allows authenticated users or attackers to perform unauthorized actions, potentially leading to i...
Sep 30, 2025This vulnerability allows attackers to execute arbitrary GraphQL queries on GitLab Language Server due to insufficient input validation. This could le...
Jul 28, 2025This vulnerability allows attackers to elevate privileges in Payment Orchestrator Service, potentially gaining unauthorized access to payment processi...
Mar 5, 2026An unauthenticated denial of service vulnerability exists in Socomec DIRIS Digiware M-70 devices running version 1.6.9. Attackers can send specially c...
Dec 1, 2025An unauthenticated denial-of-service vulnerability exists in Socomec DIRIS Digiware M-70 devices running version 1.6.9. Attackers can send specially c...
Dec 1, 2025An unauthenticated denial-of-service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 devices. Attackers c...
Dec 1, 2025An unauthenticated denial-of-service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 devices. Attackers can send s...
Dec 1, 2025This CVE describes an unauthenticated server-side request forgery (SSRF) vulnerability in Vasion Print (formerly PrinterLogic) Virtual Appliance Host ...
Sep 29, 2025This CVE describes an unauthenticated server-side request forgery (SSRF) vulnerability in Vasion Print (formerly PrinterLogic) Virtual Appliance Host ...
Sep 29, 2025CVE-2025-21355 is a missing authentication vulnerability in Microsoft Bing that allows unauthorized attackers to execute arbitrary code over the netwo...
Feb 19, 2025CVE-2024-12757 is an authentication bypass vulnerability in Nedap Librix Ecoreader that allows unauthenticated attackers to access critical functions....
Jan 17, 2025This vulnerability allows unauthenticated attackers to access configuration data of managed devices by sending specially crafted packets to Fortinet F...
Jan 14, 2025Billion Electric routers have a missing authentication vulnerability that allows unauthenticated remote attackers to access administrative functions. ...
Nov 29, 2024Chisel servers using the AUTH environment variable for authentication are vulnerable to complete authentication bypass, allowing any unauthenticated u...
Aug 26, 2024This vulnerability allows remote attackers to bypass authentication on Seiko Solutions SkyBridge devices, enabling unauthorized access to critical fun...
May 10, 2023This vulnerability in the femanager extension for TYPO3 allows unauthenticated attackers to reset passwords for all frontend users due to missing acce...
Feb 2, 2023CVE-2021-41266 is an authentication bypass vulnerability in MinIO Console when external identity provider (IDP) authentication is enabled. Attackers c...
Nov 15, 2021CVE-2021-29442 is an authentication bypass vulnerability in Nacos that allows unauthenticated attackers to access the /derby endpoint, enabling databa...
Apr 27, 2021This vulnerability allows attackers to bypass authentication in HYPR Server by exploiting missing authentication checks in Legacy APIs. It affects all...
May 23, 2023Saturn Remote Mouse Server has a critical command injection vulnerability that allows unauthenticated attackers on the local network to execute arbitr...
Feb 18, 2026This vulnerability allows unauthenticated attackers to delete directories via the uninstall API endpoint in parisneo/lollms-webui. Attackers can explo...
Mar 20, 2025This vulnerability allows attackers to bypass SSH authentication in GE Vernova Enervista UR Setup software, enabling man-in-the-middle attacks. Attack...
Mar 10, 2025An improper access control vulnerability in Fortra's FileCatalyst Workflow component allows unauthenticated attackers to upload arbitrary files via th...
Aug 19, 2025An unauthenticated remote attacker can exploit this SNMP vulnerability to access process information and trigger a system reboot via watchdog. This af...
May 26, 2025A missing authentication vulnerability in AssetView and AssetView CLOUD allows unauthenticated remote attackers to access and delete files on the serv...
Apr 2, 2025This vulnerability in open-webui v0.3.10 allows unauthenticated attackers to access the PDF generation endpoint, potentially causing denial of service...
Mar 20, 2025This vulnerability allows unauthorized users to deploy, remove, start, reload, or stop Lua applications via AppManager in SICK products. Attackers can...
Dec 6, 2024Apache Pulsar Proxy has an improper authentication vulnerability that allows unauthenticated access to the /proxy-stats endpoint. This exposes connect...
Mar 12, 2024LOYTEC building automation devices lack authentication for the LWEB-802 web interface via specific URIs, allowing unauthenticated attackers to modify ...
Nov 4, 2023This vulnerability allows attackers to execute arbitrary commands on managed devices through the SEL-5037 Grid Configurator without proper authenticat...
Aug 31, 2023This vulnerability allows attackers to bypass authentication in affected products, potentially enabling them to read or modify sensitive data, execute...
Jul 22, 2022CVE-2021-27963 is an authentication bypass vulnerability in SonLogger that allows unauthenticated attackers to create new user accounts with administr...
Mar 5, 2021OpenClaw versions before 2026.2.2 have an authentication bypass vulnerability in the WebSocket gateway connection handshake. Attackers can connect wit...
Mar 5, 2026CVE-2025-7679 is an authentication bypass vulnerability in the ASPECT system that allows unauthorized users to access protected functionality without ...
Aug 11, 2025IBM Spectrum Protect Server versions 8.1 through 8.1.26 contain an authentication bypass vulnerability due to improper session authentication. Attacke...
Jun 20, 2025A vulnerability in Veeam Backup & Replication allows low-privileged authenticated users to exploit insecure deserialization via remoting services, ena...
Dec 4, 2024CVE-2024-5718 is an unauthenticated remote code execution vulnerability in Logsign Unified SecOps Platform's cluster HTTP API. Attackers can execute a...
Nov 22, 2024A low-privileged remote attacker can modify the boot mode configuration of affected devices, potentially altering firmware upgrade processes or causin...
Nov 18, 2024This vulnerability in Oracle Trade Management allows authenticated attackers with low privileges to perform unauthorized data manipulation and access ...
Jul 16, 2024This vulnerability allows unauthenticated attackers to bypass authentication in the User Email Verification for WooCommerce WordPress plugin by exploi...
Jun 3, 2023CVE-2022-26925 is a Windows Local Security Authority (LSA) spoofing vulnerability that allows an authenticated attacker to impersonate any user on a d...
May 10, 2022About Missing Authentication (CWE-306)
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Our database tracks 675 CVEs classified as CWE-306, with 325 rated critical and 243 rated high severity. The average CVSS score for Missing Authentication vulnerabilities is 8.5.
External reference: View CWE-306 on MITRE CWE →
Monitor Missing Authentication Vulnerabilities
Get alerted when new Missing Authentication CVEs affect your infrastructure.
Start Monitoring Free