Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2022-03-30 CVE-2021-46009 Missing Authentication for Critical Function vulnerability in Totolink A3100R Firmware 5.9C.4577
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication.
network
low complexity
totolink CWE-306
critical
9.8
2022-03-30 CVE-2022-25008 Missing Authentication for Critical Function vulnerability in Totolink Ex1200T Firmware and Ex300 V2 Firmware
totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.
low complexity
totolink CWE-306
8.8
2022-03-23 CVE-2021-3589 Missing Authentication for Critical Function vulnerability in multiple products
An authorization flaw was found in Foreman Ansible.
network
high complexity
theforeman redhat CWE-306
8.0
2022-03-21 CVE-2022-23345 Missing Authentication for Critical Function vulnerability in Bigantsoft Bigant Server 5.6.06
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
network
low complexity
bigantsoft CWE-306
7.5
2022-03-21 CVE-2021-45878 Missing Authentication for Critical Function vulnerability in Garo products
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control.
network
low complexity
garo CWE-306
critical
9.1
2022-03-18 CVE-2022-26267 Missing Authentication for Critical Function vulnerability in Piwigo 12.2.0
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.
network
low complexity
piwigo CWE-306
7.5
2022-03-18 CVE-2022-22652 Missing Authentication for Critical Function vulnerability in Apple Iphone OS
The GSMA authentication panel could be presented on the lock screen.
low complexity
apple CWE-306
6.1
2022-03-17 CVE-2022-26501 Missing Authentication for Critical Function vulnerability in Veeam Backup & Replication
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
network
low complexity
veeam CWE-306
critical
9.8
2022-03-17 CVE-2021-44259 Missing Authentication for Critical Function vulnerability in Wavlink Wl-Wn531G3 Firmware A42W1.27.620180418
A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication.
network
low complexity
wavlink CWE-306
critical
9.8
2022-03-17 CVE-2021-44260 Missing Authentication for Critical Function vulnerability in Wavlink Wl-Wn531G3 Firmware A42W1.27.620180418
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication.
network
low complexity
wavlink CWE-306
7.5