Vulnerabilities > Missing Authentication for Critical Function
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-27 | CVE-2021-45232 | Missing Authentication for Critical Function vulnerability in Apache Apisix Dashboard In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication. | 9.8 |
2021-12-17 | CVE-2021-36779 | Missing Authentication for Critical Function vulnerability in Linuxfoundation Longhorn A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. | 9.6 |
2021-12-17 | CVE-2021-36780 | Missing Authentication for Critical Function vulnerability in Linuxfoundation Longhorn A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica instance granting it the ability to read and write data to and from a replica that they should not have access to. | 8.1 |
2021-12-15 | CVE-2021-36888 | Missing Authentication for Critical Function vulnerability in Blocksera Image Hover Effects Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin. | 9.8 |
2021-12-13 | CVE-2021-22279 | Missing Authentication for Critical Function vulnerability in ABB Omnicore C30 Firmware A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port. | 9.8 |
2021-12-13 | CVE-2021-44152 | Missing Authentication for Critical Function vulnerability in Reprisesoftware Reprise License Manager An issue was discovered in Reprise RLM 14.2. | 9.8 |
2021-12-07 | CVE-2021-34543 | Missing Authentication for Critical Function vulnerability in BKW Solar-Log 500 Firmware The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. | 7.5 |
2021-11-29 | CVE-2021-38147 | Missing Authentication for Critical Function vulnerability in Wipro Holmes 20.4.1 Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel. | 7.5 |
2021-11-29 | CVE-2021-38283 | Missing Authentication for Critical Function vulnerability in Wipro Holmes 20.4.1 Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a predictable /log URI. | 7.5 |
2021-11-29 | CVE-2021-44077 | Missing Authentication for Critical Function vulnerability in Zohocorp products Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. | 9.8 |