Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2022-03-10 CVE-2022-20060 Missing Authentication for Critical Function vulnerability in Google Android 10.0/11.0/12.0
In preloader (usb), there is a possible permission bypass due to a missing proper image authentication.
low complexity
google CWE-306
6.6
2022-03-04 CVE-2021-46384 Missing Authentication for Critical Function vulnerability in Mingsoft Mcms
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE.
network
low complexity
mingsoft CWE-306
critical
9.8
2022-02-26 CVE-2022-25359 Missing Authentication for Critical Function vulnerability in Iclinks Scadaflex II Firmware and Weblib
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
network
low complexity
iclinks CWE-306
critical
9.1
2022-02-24 CVE-2020-10640 Missing Authentication for Critical Function vulnerability in Emerson Openenterprise Scada Server 2.8.3/3.1/3.3.3
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.
network
low complexity
emerson CWE-306
critical
9.8
2022-02-14 CVE-2021-46371 Missing Authentication for Critical Function vulnerability in Antd-Admin Project Antd-Admin 5.5.0
antd-admin 5.5.0 is affected by an incorrect access control vulnerability.
network
low complexity
antd-admin-project CWE-306
7.5
2022-02-14 CVE-2022-0188 Missing Authentication for Critical Function vulnerability in Niteothemes CMP
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
network
low complexity
niteothemes CWE-306
5.3
2022-02-11 CVE-2021-22805 Missing Authentication for Critical Function vulnerability in Schneider-Electric Interactive Graphical Scada System Data Collector
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages.
network
low complexity
schneider-electric CWE-306
critical
9.1
2022-02-11 CVE-2021-22823 Missing Authentication for Critical Function vulnerability in Schneider-Electric Interactive Graphical Scada System Data Collector
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages.
network
low complexity
schneider-electric CWE-306
critical
9.1
2022-02-10 CVE-2021-31814 Missing Authentication for Critical Function vulnerability in Stormshield Network Security
In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client.
local
low complexity
stormshield CWE-306
6.1
2022-02-10 CVE-2022-24111 Missing Authentication for Critical Function vulnerability in Mahara
In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known.
network
low complexity
mahara CWE-306
5.3