Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2022-04-11 CVE-2022-24829 Missing Authentication for Critical Function vulnerability in Garden
Garden is an automation platform for Kubernetes development and testing.
network
garden CWE-306
4.3
2022-04-08 CVE-2022-24820 Missing Authentication for Critical Function vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-306
5.3
2022-04-08 CVE-2021-43483 Missing Authentication for Critical Function vulnerability in Claro Kaon Cg3000 Firmware 1.00.67
An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update the configuraiton without authentication.
low complexity
claro CWE-306
5.2
2022-04-07 CVE-2020-27376 Missing Authentication for Critical Function vulnerability in Drtrustusa Icheck Connect BP Monitor BP Testing 118 Firmware 1.2.1
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.
low complexity
drtrustusa CWE-306
8.3
2022-04-06 CVE-2022-1248 Missing Authentication for Critical Function vulnerability in SAP Information System Project SAP Information System 1.0
A vulnerability was found in SAP Information System 1.0 which has been rated as critical.
network
low complexity
sap-information-system-project CWE-306
7.3
2022-04-05 CVE-2022-25245 Missing Authentication for Critical Function vulnerability in Zohocorp Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
network
low complexity
zohocorp CWE-306
5.3
2022-04-04 CVE-2021-33008 Missing Authentication for Critical Function vulnerability in Aveva System Platform 2020
AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity.
network
low complexity
aveva CWE-306
7.5
2022-04-01 CVE-2020-14479 Missing Authentication for Critical Function vulnerability in Inductiveautomation Ignition 7.7.2
Sensitive information can be obtained through the handling of serialized data.
network
low complexity
inductiveautomation CWE-306
5.0
2022-04-01 CVE-2021-20238 Missing Authentication for Critical Function vulnerability in Redhat products
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication.
network
high complexity
redhat CWE-306
3.7
2022-04-01 CVE-2022-0922 Missing Authentication for Critical Function vulnerability in Philips E-Alert Firmware 2.1
The software does not perform any authentication for critical system functionality.
5.7