Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2024-02-18 CVE-2022-48621 Missing Authentication for Critical Function vulnerability in Huawei Emui and Harmonyos
Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulnerability may affect service confidentiality.
network
low complexity
huawei CWE-306
7.5
2024-02-14 CVE-2024-25618 Missing Authentication for Critical Function vulnerability in Joinmastodon Mastodon
Mastodon is a free, open-source social network server based on ActivityPub.
network
high complexity
joinmastodon CWE-306
7.4
2024-02-14 CVE-2024-23783 Missing Authentication for Critical Function vulnerability in Sharp Jh-Rv11 Firmware and Jh-Rvb1 Firmware
Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product without authentication.
low complexity
sharp CWE-306
8.8
2024-02-06 CVE-2023-40545 Missing Authentication for Critical Function vulnerability in Pingidentity Pingfederate 11.3.0
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
network
low complexity
pingidentity CWE-306
critical
9.8
2024-02-06 CVE-2024-23917 Missing Authentication for Critical Function vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
network
low complexity
jetbrains CWE-306
critical
9.8
2024-02-01 CVE-2023-49115 Missing Authentication for Critical Function vulnerability in Machinesense Feverwarn Firmware
MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.
network
low complexity
machinesense CWE-306
7.5
2024-02-01 CVE-2023-49617 Missing Authentication for Critical Function vulnerability in Machinesense Feverwarn Firmware
The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication.
network
low complexity
machinesense CWE-306
critical
9.1
2024-02-01 CVE-2023-6221 Missing Authentication for Critical Function vulnerability in Machinesense Feverwarn Firmware
The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others is insufficiently protected against unauthorized access.
network
low complexity
machinesense CWE-306
6.5
2024-02-01 CVE-2024-22449 Missing Authentication for Critical Function vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability.
local
low complexity
dell CWE-306
7.8
2024-01-26 CVE-2024-23618 Missing Authentication for Critical Function vulnerability in Commscope Arris Surfboard Sbg6950Ac2 Firmware
An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices.
network
low complexity
commscope CWE-306
critical
9.8