Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2022-03-21 CVE-2022-23345 Missing Authentication for Critical Function vulnerability in Bigantsoft Bigant Server 5.6.06
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
network
low complexity
bigantsoft CWE-306
7.5
2022-03-21 CVE-2021-45878 Missing Authentication for Critical Function vulnerability in Garo products
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control.
network
low complexity
garo CWE-306
critical
9.1
2022-03-18 CVE-2022-26267 Missing Authentication for Critical Function vulnerability in Piwigo 12.2.0
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.
network
low complexity
piwigo CWE-306
7.5
2022-03-18 CVE-2022-22652 Missing Authentication for Critical Function vulnerability in Apple Iphone OS
The GSMA authentication panel could be presented on the lock screen.
low complexity
apple CWE-306
6.1
2022-03-17 CVE-2022-26501 Missing Authentication for Critical Function vulnerability in Veeam Backup & Replication
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
network
low complexity
veeam CWE-306
critical
9.8
2022-03-17 CVE-2021-44259 Missing Authentication for Critical Function vulnerability in Wavlink Wl-Wn531G3 Firmware A42W1.27.620180418
A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication.
network
low complexity
wavlink CWE-306
critical
9.8
2022-03-17 CVE-2021-44260 Missing Authentication for Critical Function vulnerability in Wavlink Wl-Wn531G3 Firmware A42W1.27.620180418
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication.
network
low complexity
wavlink CWE-306
7.5
2022-03-17 CVE-2021-44261 Missing Authentication for Critical Function vulnerability in Netgear products
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication.
network
low complexity
netgear CWE-306
5.3
2022-03-17 CVE-2021-44262 Missing Authentication for Critical Function vulnerability in Netgear products
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication.
network
low complexity
netgear CWE-306
7.5
2022-03-16 CVE-2022-25247 Missing Authentication for Critical Function vulnerability in PTC Axeda Agent and Axeda Desktop Server
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication.
network
low complexity
ptc CWE-306
critical
9.8