Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2019-11-06 CVE-2006-0062 Missing Authentication for Critical Function vulnerability in Sillycycle Xlockmore 5.13
xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.
network
low complexity
sillycycle CWE-306
7.5
2019-11-06 CVE-2006-0061 Missing Authentication for Critical Function vulnerability in Sillycycle Xlockmore 5.13/5.22
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession.
network
low complexity
sillycycle CWE-306
7.5
2019-10-31 CVE-2019-18230 Missing Authentication for Critical Function vulnerability in Honeywell products
Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.
network
low complexity
honeywell CWE-306
5.0
2019-10-31 CVE-2019-16907 Missing Authentication for Critical Function vulnerability in Infosysta In-App & Desktop Notifications 1.6.13J8
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira.
network
low complexity
infosysta CWE-306
5.0
2019-10-31 CVE-2019-16906 Missing Authentication for Critical Function vulnerability in Infosysta In-App & Desktop Notifications 1.6.13J8
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira.
network
low complexity
infosysta CWE-306
5.0
2019-10-31 CVE-2019-13547 Missing Authentication for Critical Function vulnerability in Advantech Wise-Paas/Rmm 3.3.29
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior.
network
low complexity
advantech CWE-306
critical
10.0
2019-10-31 CVE-2019-18465 Missing Authentication for Critical Function vulnerability in Ipswitch Moveit Transfer 11.1/11.1.1
In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface.
network
ipswitch CWE-306
6.8
2019-10-29 CVE-2019-3978 Missing Authentication for Critical Function vulnerability in Mikrotik Routeros
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291.
network
low complexity
mikrotik CWE-306
5.0
2019-10-25 CVE-2019-13549 Missing Authentication for Critical Function vulnerability in Carel Pcoweb Firmware A1.5.3/A2.0.4/B1.2.4
Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4.
network
low complexity
carel CWE-306
5.0
2019-10-25 CVE-2019-13525 Missing Authentication for Critical Function vulnerability in Honeywell Ip-Ak2 Firmware
In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without authentication over the network.
network
low complexity
honeywell CWE-306
5.0