Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-306

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

2,698
Assigned CVEs
29th
Commonality Rank
8.1
Avg CVSS
1.9%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-306 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

2,698 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-35273CRITICAL
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8
Jun 11, 20269.899YESYES
CVE-2026-20253CRITICAL
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service
Jun 10, 20269.899YESYES
CVE-2026-41940CRITICAL
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the
Apr 29, 20269.899YESYES
CVE-2026-33017CRITICAL
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building
Mar 20, 20269.899YESYES
CVE-2025-3248CRITICAL
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to e
Apr 7, 20259.899YESYES
CVE-2024-5910CRITICAL
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. N
Jul 10, 20249.899YESYES
CVE-2023-42793CRITICAL
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
Sep 19, 20239.899YESYES
CVE-2022-1388CRITICAL
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x ver
May 5, 20229.899YESYES
CVE-2020-13927CRITICAL
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Ai
Nov 10, 20209.899YESYES
CVE-2019-9082HIGH
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_
Feb 24, 20198.899YESYES
View all 2,698 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
11%
19%
5.0-5.9
8%
16%
6.0-6.9
24%
26%
7.0-7.9
14%
11%
8.0-8.9
40%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
51 CVEs
1.9% of CVEs· 94th percentile
Metasploit
80 CVEs
3.0% of CVEs· 95th percentile
Nuclei
137 CVEs
5.1% of CVEs· 96th percentile
ExploitDB
58 CVEs
2.1% of CVEs· 88th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products