CWE-306 · 2 686 записей
Отсутствие аутентификации для критической функции
Почему это происходит?
Функция, добавленная для разработки или поддержки, попадает в продуктивную среду без аутентификации. Нередко расчёт делается на то, что она «доступна только из внутренней сети».
Уязвимый и исправленный код
Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.
Уязвимый код
// Добавлено для службы поддержкиapp.post("/maintenance/reset", resetDevice);Исправленный код
if (config.maintenanceEnabled) { app.post( "/maintenance/reset", requireSession, requireRole("admin"), resetDevice );}Как предотвратить
- 01Исключайте функции обслуживания и отладки из продуктивной сборки.
- 02Если функцию нужно оставить, защитите её проверкой прав и отдельным флагом конфигурации.
- 03Не подменяйте аутентификацию сетевым расположением.
CVE этого класса
2 688 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2025-32433Готовый эксплойт | Erlang/OTP SSH Vulnerable to Pre-Authentication RCEerlang · erlang\/otp · CWE-306 | Критическая10,0 | KEV | 98,8 % | 16 апр. 2025 г. |
99Срочно | CVE-2025-3248Готовый эксплойт | Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/codelangflow · langflow · CWE-306 | Критическая9,8 | KEV | 100,0 % | 7 апр. 2025 г. |
99Срочно | CVE-2022-1388Готовый эксплойт | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior f5 · big-ip access policy manager · CWE-306 | Критическая9,8 | KEV | 100,0 % | 5 мая 2022 г. |
99Срочно | CVE-2021-37415Готовый эксплойт | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authenticatiozohocorp · manageengine servicedesk plus · CWE-306 | Критическая9,8 | KEV | 99,8 % | 1 сент. 2021 г. |
99Срочно | CVE-2020-13927Готовый эксплойт | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security riapache · airflow · CWE-306 | Критическая9,8 | KEV | 99,8 % | 10 нояб. 2020 г. |
99Срочно | CVE-2022-21587Готовый эксплойт | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).oracle · e-business suite · CWE-306 | Критическая9,8 | KEV | 98,3 % | 18 окт. 2022 г. |
98Срочно | CVE-2020-6207Готовый эксплойт | SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication forsap · solution manager · CWE-306 | Критическая9,8 | KEV | 98,1 % | 10 мар. 2020 г. |
98Срочно | CVE-2026-20253Готовый эксплойт | Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprisesplunk · splunk · CWE-306 | Критическая9,8 | KEV | 96,9 % | 10 июн. 2026 г. |
98Срочно | CVE-2021-35587Готовый эксплойт | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent).oracle · access manager · CWE-306 | Критическая9,8 | KEV | 96,3 % | 19 янв. 2022 г. |
98Срочно | CVE-2020-6287Готовый эксплойт | SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows ansap · netweaver application server java · CWE-306 | Критическая10,0 | KEV | 94,7 % | 14 июл. 2020 г. |
97Срочно | CVE-2024-0012Готовый эксплойт | PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)paloaltonetworks · pan-os · CWE-306 | Критическая9,3 | KEV | 99,8 % | 18 нояб. 2024 г. |
97Срочно | CVE-2026-41940Готовый эксплойт | WebPros cPanel and WHM Authentication Bypass via Login Flowcpanel · cpanel · CWE-306 | Критическая9,3 | KEV | 98,5 % | 29 апр. 2026 г. |
97Срочно | CVE-2024-47575Готовый эксплойт | A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, Fofortinet · fortimanager · CWE-306 | Критическая9,8 | KEV | 94,8 % | 23 окт. 2024 г. |
97Срочно | CVE-2021-44077Готовый эксплойт | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unzohocorp · manageengine servicedesk plus · CWE-306 | Критическая9,8 | KEV | 93,3 % | 29 нояб. 2021 г. |
97Срочно | CVE-2024-11680Готовый эксплойт | ProjectSend Unauthenticated Configuration Modificationprojectsend · projectsend · CWE-306 | Критическая9,8 | KEV | 91,7 % | 26 нояб. 2024 г. |
96Срочно | CVE-2020-3952Готовый эксплойт | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)vmware · vcenter server · CWE-306 | Критическая9,8 | KEV | 90,4 % | 10 апр. 2020 г. |
96Срочно | CVE-2025-61757Готовый эксплойт | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices).oracle · identity manager · CWE-306 | Критическая9,8 | KEV | 88,6 % | 21 окт. 2025 г. |
95Срочно | CVE-2025-0108Готовый эксплойт | PAN-OS: Authentication Bypass in the Management Web Interfacepaloaltonetworks · pan-os · CWE-306 | Высокая8,8 | KEV | 98,5 % | 12 февр. 2025 г. |
95Срочно | CVE-2024-5910Готовый эксплойт | Expedition: Missing Authentication Leads to Admin Account Takeoverpaloaltonetworks · expedition · CWE-306 | Критическая9,3 | KEV | 91,8 % | 10 июл. 2024 г. |
95Срочно | CVE-2022-26143Готовый эксплойт | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers tomitel · micollab · CWE-306 | Критическая9,8 | KEV | 87,3 % | 10 мар. 2022 г. |
95Срочно | CVE-2024-51567Готовый эксплойт | upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication andcyberpanel · cyberpanel · CWE-306 | Критическая9,8 | KEV | 86,6 % | 29 окт. 2024 г. |
93Срочно | CVE-2026-24423Готовый эксплойт | SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub APIsmartertools · smartermail · CWE-306 | Критическая9,3 | KEV | 88,2 % | 23 янв. 2026 г. |
90Срочно | CVE-2017-10271Готовый эксплойт | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security).oracle · weblogic server · CWE-306 | Высокая7,5 | KEV | 100,0 % | 19 окт. 2017 г. |
85Срочно | CVE-2022-24990Готовый эксплойт | TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/aterra-master · terramaster operating system · CWE-306 | Высокая7,5 | KEV | 83,0 % | 7 февр. 2023 г. |
84Срочно | CVE-2023-27532Готовый эксплойт | Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained.veeam · veeam backup \& replication · CWE-306 | Высокая7,5 | KEV | 81,3 % | 10 мар. 2023 г. |
- CVE-2025-32433100Срочно
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 99 %erlang · erlang\/otp16 апр. 2025 г.
- CVE-2025-324899Срочно
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %langflow · langflow7 апр. 2025 г.
- CVE-2022-138899Срочно
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %f5 · big-ip access policy manager5 мая 2022 г.
- CVE-2021-3741599Срочно
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authenticatio
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zohocorp · manageengine servicedesk plus1 сент. 2021 г.
- CVE-2020-1392799Срочно
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · airflow10 нояб. 2020 г.
- CVE-2022-2158799Срочно
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %oracle · e-business suite18 окт. 2022 г.
- CVE-2020-620798Срочно
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %sap · solution manager10 мар. 2020 г.
- CVE-2026-2025398Срочно
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %splunk · splunk10 июн. 2026 г.
- CVE-2021-3558798Срочно
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 96 %oracle · access manager19 янв. 2022 г.
- CVE-2020-628798Срочно
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 95 %sap · netweaver application server java14 июл. 2020 г.
- CVE-2024-001297Срочно
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 100 %paloaltonetworks · pan-os18 нояб. 2024 г.
- CVE-2026-4194097Срочно
WebPros cPanel and WHM Authentication Bypass via Login Flow
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 99 %cpanel · cpanel29 апр. 2026 г.
- CVE-2024-4757597Срочно
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, Fo
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %fortinet · fortimanager23 окт. 2024 г.
- CVE-2021-4407797Срочно
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to un
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %zohocorp · manageengine servicedesk plus29 нояб. 2021 г.
- CVE-2024-1168097Срочно
ProjectSend Unauthenticated Configuration Modification
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %projectsend · projectsend26 нояб. 2024 г.
- CVE-2020-395296Срочно
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %vmware · vcenter server10 апр. 2020 г.
- CVE-2025-6175796Срочно
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 89 %oracle · identity manager21 окт. 2025 г.
- CVE-2025-010895Срочно
PAN-OS: Authentication Bypass in the Management Web Interface
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 98 %paloaltonetworks · pan-os12 февр. 2025 г.
- CVE-2024-591095Срочно
Expedition: Missing Authentication Leads to Admin Account Takeover
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 92 %paloaltonetworks · expedition10 июл. 2024 г.
- CVE-2022-2614395Срочно
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %mitel · micollab10 мар. 2022 г.
- CVE-2024-5156795Срочно
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %cyberpanel · cyberpanel29 окт. 2024 г.
- CVE-2026-2442393Срочно
SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 88 %smartertools · smartermail23 янв. 2026 г.
- CVE-2017-1027190Срочно
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security).
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %oracle · weblogic server19 окт. 2017 г.
- CVE-2022-2499085Срочно
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/a
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 83 %terra-master · terramaster operating system7 февр. 2023 г.
- CVE-2023-2753284Срочно
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 81 %veeam · veeam backup \& replication10 мар. 2023 г.