Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2020-04-29 CVE-2020-12478 Missing Authentication for Critical Function vulnerability in Teampass 2.1.27.36
TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root.
network
low complexity
teampass CWE-306
7.5
2020-04-28 CVE-2020-10641 Missing Authentication for Critical Function vulnerability in Inductiveautomation Ignition Gateway
An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication.
network
low complexity
inductiveautomation CWE-306
7.5
2020-04-27 CVE-2020-12266 Missing Authentication for Critical Function vulnerability in Wavlink products
An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage.
network
low complexity
wavlink CWE-306
7.5
2020-04-24 CVE-2020-5870 Missing Authentication for Critical Function vulnerability in F5 Big-Iq Centralized Management
In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer.
low complexity
f5 CWE-306
8.1
2020-04-23 CVE-2018-21132 Missing Authentication for Critical Function vulnerability in Netgear Wac505 Firmware and Wac510 Firmware
Certain NETGEAR devices are affected by authentication bypass.
network
low complexity
netgear CWE-306
critical
9.8
2020-04-22 CVE-2020-11649 Missing Authentication for Critical Function vulnerability in Gitlab
An issue was discovered in GitLab CE and EE 8.15 through 12.9.2.
network
low complexity
gitlab CWE-306
6.5
2020-04-22 CVE-2019-19104 Missing Authentication for Critical Function vulnerability in multiple products
The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessing a specific uniform resource locator (URL) , violating the access-control (ACL) rules.
network
low complexity
abb busch-jaeger CWE-306
critical
9.8
2020-04-20 CVE-2020-9278 Missing Authentication for Critical Function vulnerability in Dlink Dsl-2640B Firmware Eu4.01B
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices.
network
low complexity
dlink CWE-306
critical
9.1
2020-04-20 CVE-2020-9275 Missing Authentication for Critical Function vulnerability in Dlink Dsl-2640B Firmware Eu4.01B
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices.
network
low complexity
dlink CWE-306
critical
9.8
2020-04-20 CVE-2020-11946 Missing Authentication for Critical Function vulnerability in Zohocorp Manageengine Opmanager 12.5
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
network
low complexity
zohocorp CWE-306
7.5