Vulnerabilities > Missing Authentication for Critical Function
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-06-12 | CVE-2019-0312 | Missing Authentication for Critical Function vulnerability in SAP Netweaver Process Integration Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. | 5.3 |
2019-06-12 | CVE-2017-15123 | Missing Authentication for Critical Function vulnerability in Redhat Cloudforms Management Engine A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. | 5.3 |
2019-06-11 | CVE-2019-3411 | Missing Authentication for Critical Function vulnerability in ZTE Mf920 Firmware All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. | 7.5 |
2019-06-10 | CVE-2019-9881 | Missing Authentication for Critical Function vulnerability in Wpengine Wpgraphql 0.2.3 The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled. | 5.3 |
2019-06-10 | CVE-2019-9880 | Missing Authentication for Critical Function vulnerability in Wpengine Wpgraphql 0.2.3 An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. | 9.1 |
2019-06-10 | CVE-2019-9879 | Missing Authentication for Critical Function vulnerability in Wpengine Wpgraphql 0.2.3 The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. | 9.8 |
2019-06-06 | CVE-2019-6451 | Missing Authentication for Critical Function vulnerability in Soyal Ar-727H Firmware and Ar-829Ev5 Firmware On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST access. | 7.5 |
2019-05-31 | CVE-2019-9105 | Missing Authentication for Critical Function vulnerability in Saet Tebe Small Firmware and Webapp The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of API calls without authentication, as demonstrated by retrieving password hashes via an inc/utils/REST_API.php?command=CallAPI&customurl=alladminusers call. | 7.5 |
2019-05-31 | CVE-2019-10046 | Missing Authentication for Critical Function vulnerability in Pydio 8.2.2 An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information. | 5.3 |
2019-05-31 | CVE-2019-9871 | Missing Authentication for Critical Function vulnerability in Jector Fm-K75 Firmware Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission. | 9.8 |