Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2021-03-03 CVE-2021-27215 Missing Authentication for Critical Function vulnerability in Genua Genuagate 10.1/9.0/9.6.0
An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4.
network
low complexity
genua CWE-306
critical
9.8
2021-02-27 CVE-2019-25020 Missing Authentication for Critical Function vulnerability in Scytl Secure Vote 2.1
An issue was discovered in Scytl sVote 2.1.
network
low complexity
scytl CWE-306
7.5
2021-02-26 CVE-2019-11684 Missing Authentication for Critical Function vulnerability in Bosch products
Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system.
network
low complexity
bosch CWE-306
critical
9.8
2021-02-24 CVE-2021-20662 Missing Authentication for Critical Function vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.0/6.00
Missing authentication for critical function in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to alter the setting information without the access privileges via unspecified vectors.
network
low complexity
contec CWE-306
7.5
2021-02-17 CVE-2020-36245 Missing Authentication for Critical Function vulnerability in Gramaddict
GramAddict through 1.2.3 allows remote attackers to execute arbitrary code because of use of UIAutomator2 and ATX-Agent.
low complexity
gramaddict CWE-306
8.8
2021-02-17 CVE-2021-26697 Missing Authentication for Critical Function vulnerability in Apache Airflow 2.0.0
The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0.
network
low complexity
apache CWE-306
5.3
2021-02-16 CVE-2021-20067 Missing Authentication for Critical Function vulnerability in Racom M!Dge Firmware 4.4.40.105
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authentication.
network
low complexity
racom CWE-306
5.3
2021-02-09 CVE-2020-26192 Missing Authentication for Critical Function vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability.
local
low complexity
dell CWE-306
7.8
2021-02-09 CVE-2021-21472 Missing Authentication for Critical Function vulnerability in SAP Software Provisioning Manager 1.0
SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perform various security attacks like Directory Traversal, Password Brute force Attack, SMB Relay attack, Security Downgrade.
network
low complexity
sap CWE-306
8.8
2021-02-05 CVE-2020-10537 Missing Authentication for Critical Function vulnerability in Epikur 20.1.0.1
An issue was discovered in Epikur before 20.1.1.
local
low complexity
epikur CWE-306
7.8