Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2024-05-29 CVE-2024-36470 Missing Authentication for Critical Function vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
network
low complexity
jetbrains CWE-306
critical
9.8
2024-05-08 CVE-2024-2860 Missing Authentication for Critical Function vulnerability in Broadcom Brocade Sannav
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw.
local
low complexity
broadcom CWE-306
7.8
2024-05-06 CVE-2024-3661 Missing Authentication for Critical Function vulnerability in multiple products
DHCP can add routes to a client’s routing table via the classless static route option (121).
7.6
2024-05-03 CVE-2023-27357 Missing Authentication for Critical Function vulnerability in Netgear Rax30 Firmware
NETGEAR RAX30 GetInfo Missing Authentication Information Disclosure Vulnerability.
low complexity
netgear CWE-306
6.5
2024-04-25 CVE-2023-51478 Missing Authentication for Critical Function vulnerability in Buildapp Build APP Online
Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.
network
low complexity
buildapp CWE-306
critical
9.8
2024-03-20 CVE-2024-28179 Missing Authentication for Critical Function vulnerability in Jupyter Server Proxy
Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provides authenticated web access.
network
low complexity
jupyter CWE-306
critical
9.8
2024-03-15 CVE-2024-2450 Missing Authentication for Critical Function vulnerability in Mattermost Server
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take over other user accounts via a crafted switch request under specific conditions.
network
low complexity
mattermost CWE-306
8.8
2024-02-18 CVE-2022-48621 Missing Authentication for Critical Function vulnerability in Huawei Emui and Harmonyos
Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulnerability may affect service confidentiality.
network
low complexity
huawei CWE-306
7.5
2024-02-14 CVE-2024-25618 Missing Authentication for Critical Function vulnerability in Joinmastodon Mastodon
Mastodon is a free, open-source social network server based on ActivityPub.
network
high complexity
joinmastodon CWE-306
7.4
2024-02-14 CVE-2024-23783 Missing Authentication for Critical Function vulnerability in Sharp Jh-Rv11 Firmware and Jh-Rvb1 Firmware
Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product without authentication.
low complexity
sharp CWE-306
8.8