Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2022-08-11 CVE-2022-2765 Missing Authentication for Critical Function vulnerability in Company Website CMS Project Company Website CMS 1.0
A vulnerability was found in SourceCodester Company Website CMS 1.0.
network
low complexity
company-website-cms-project CWE-306
critical
9.8
2022-08-10 CVE-2022-2242 Missing Authentication for Critical Function vulnerability in Kuka Systemsoftware V/Kss
The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when access control is not available or not enabled (default).
network
low complexity
kuka CWE-306
critical
9.8
2022-08-03 CVE-2022-35865 Missing Authentication for Critical Function vulnerability in BMC Track-It!
This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109.
network
low complexity
bmc CWE-306
critical
9.8
2022-07-28 CVE-2022-30313 Missing Authentication for Critical Function vulnerability in Honeywell Safety Manager Firmware
Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function.
network
low complexity
honeywell CWE-306
7.5
2022-07-27 CVE-2022-36884 Missing Authentication for Critical Function vulnerability in Jenkins GIT
The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.
network
low complexity
jenkins CWE-306
5.3
2022-07-26 CVE-2022-30276 Missing Authentication for Critical Function vulnerability in Motorola products
The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement.
network
low complexity
motorola CWE-306
7.5
2022-07-26 CVE-2022-36129 Missing Authentication for Critical Function vulnerability in Hashicorp Vault
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure.
network
low complexity
hashicorp CWE-306
critical
9.1
2022-07-26 CVE-2022-29951 Missing Authentication for Critical Function vulnerability in Jtekt products
JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication.
network
low complexity
jtekt CWE-306
critical
9.1
2022-07-26 CVE-2022-29952 Missing Authentication for Critical Function vulnerability in Bakerhughes products
Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication.
network
low complexity
bakerhughes CWE-306
critical
9.1
2022-07-26 CVE-2022-29957 Missing Authentication for Critical Function vulnerability in Emerson Deltav Distributed Control System
The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication.
local
low complexity
emerson CWE-306
7.8