Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2023-02-20 CVE-2023-23453 Missing Authentication for Critical Function vulnerability in Sick Fx0-Gent00000 Firmware and Fx0-Gent00010 Firmware
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.
network
low complexity
sick CWE-306
critical
9.8
2023-02-20 CVE-2022-44216 Missing Authentication for Critical Function vulnerability in SIR Gnuboard 5.5.4/5.5.5
Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions.
network
low complexity
sir CWE-306
7.5
2023-02-20 CVE-2023-25570 Missing Authentication for Critical Function vulnerability in Apolloconfig Apollo
Apollo is a configuration management system.
network
low complexity
apolloconfig CWE-306
7.5
2023-02-19 CVE-2023-0919 Missing Authentication for Critical Function vulnerability in Kavitareader Kavita
Missing Authentication for Critical Function in GitHub repository kareadita/kavita prior to 0.7.0.
network
low complexity
kavitareader CWE-306
3.5
2023-02-18 CVE-2023-0906 Missing Authentication for Critical Function vulnerability in Online Pizza Ordering System Project Online Pizza Ordering System 1.0
A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0.
network
low complexity
online-pizza-ordering-system-project CWE-306
critical
9.8
2023-02-16 CVE-2022-47703 Missing Authentication for Critical Function vulnerability in Tianjie Cpe906-3 and Cpe906-3 Firmware
TIANJIE CPE906-3 is vulnerable to password disclosure.
network
low complexity
tianjie CWE-306
7.5
2023-02-16 CVE-2022-27891 Missing Authentication for Critical Function vulnerability in Palantir Gotham
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session.
network
low complexity
palantir CWE-306
5.3
2023-02-15 CVE-2023-0102 Missing Authentication for Critical Function vulnerability in Ls-Electric Xbc-Dn32U Firmware 01.80
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command.
network
low complexity
ls-electric CWE-306
critical
9.1
2023-02-15 CVE-2023-22803 Missing Authentication for Critical Function vulnerability in Ls-Electric Xbc-Dn32U Firmware 01.80
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the PLC.
network
low complexity
ls-electric CWE-306
7.5
2023-02-15 CVE-2023-22804 Missing Authentication for Critical Function vulnerability in Ls-Electric Xbc-Dn32U Firmware 01.80
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC.
network
low complexity
ls-electric CWE-306
critical
9.8