Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2021-05-25 CVE-2021-30190 Missing Authentication for Critical Function vulnerability in Codesys V2 web Server
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
network
low complexity
codesys CWE-306
critical
9.8
2021-05-17 CVE-2020-4670 Missing Authentication for Critical Function vulnerability in IBM Planning Analytics Cloud and Planning Analytics Local
IBM Planning Analytics Local 2.0 connects to a Redis server.
network
low complexity
ibm CWE-306
critical
9.1
2021-05-17 CVE-2021-32453 Missing Authentication for Critical Function vulnerability in Sitel-Sa Cap/Prx Firmware 5.2.01
SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network, to access via HTTP to the internal configuration database of the device without any authentication.
local
low complexity
sitel-sa CWE-306
3.3
2021-05-13 CVE-2021-20998 Missing Authentication for Critical Function vulnerability in Wago products
In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.
network
low complexity
wago CWE-306
critical
9.8
2021-05-07 CVE-2021-27570 Missing Authentication for Critical Function vulnerability in Remotemouse Emote Remote Mouse
An issue was discovered in Emote Remote Mouse through 3.015.
network
low complexity
remotemouse CWE-306
5.3
2021-05-07 CVE-2021-27571 Missing Authentication for Critical Function vulnerability in Remotemouse Emote Remote Mouse
An issue was discovered in Emote Remote Mouse through 4.0.0.0.
network
low complexity
remotemouse CWE-306
5.3
2021-05-07 CVE-2020-36125 Missing Authentication for Critical Function vulnerability in Paxtechnology Paxstore 7.0.820200511171508
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive operations can be bypassed remotely by an authenticated attacker through requesting the endpoint directly.
network
low complexity
paxtechnology CWE-306
7.1
2021-05-06 CVE-2021-29203 Missing Authentication for Critical Function vulnerability in HP Edgeline Infrastructure Manager 1.21
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22.
network
low complexity
hp CWE-306
critical
9.8
2021-05-06 CVE-2021-31793 Missing Authentication for Critical Function vulnerability in Nightowlsp Wdb-20 Firmware 20190314
An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams from the doorbell.
network
low complexity
nightowlsp CWE-306
7.5
2021-05-06 CVE-2021-1499 Missing Authentication for Critical Function vulnerability in Cisco Hyperflex HX Data Platform
A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device.
network
low complexity
cisco CWE-306
5.3