Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2020-01-09 CVE-2014-3449 Missing Authentication for Critical Function vulnerability in BSS Continuity CMS Project BSS Continuty CMS 4.2.22640.0
BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability
network
low complexity
bss-continuity-cms-project CWE-306
critical
9.8
2020-01-08 CVE-2020-6170 Missing Authentication for Critical Function vulnerability in Genexis Platinum-4410 Firmware 1.28
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.
network
low complexity
genexis CWE-306
critical
9.8
2020-01-07 CVE-2019-17146 Missing Authentication for Critical Function vulnerability in Dlink Dcs-935L Firmware and Dcs-960L Firmware
This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102.
network
low complexity
dlink CWE-306
critical
9.8
2020-01-06 CVE-2019-16271 Missing Authentication for Critical Function vulnerability in Dten D5 Firmware and D7 Firmware
DTEN D5 and D7 before 1.3.2 devices allows remote attackers to read saved whiteboard image PDF documents via storage/emulated/0/Notes/PDF on TCP port 8080 without authentication.
network
low complexity
dten CWE-306
5.3
2019-12-30 CVE-2018-20507 Missing Authentication for Critical Function vulnerability in Gitlab
An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1.
network
low complexity
gitlab CWE-306
5.3
2019-12-26 CVE-2012-2736 Missing Authentication for Critical Function vulnerability in multiple products
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
local
low complexity
gnome debian canonical opensuse CWE-306
4.4
2019-12-18 CVE-2019-5080 Missing Authentication for Critical Function vulnerability in Wago PFC 100 Firmware and PFC 200 Firmware
An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12).
network
low complexity
wago CWE-306
critical
9.1
2019-12-18 CVE-2019-5078 Missing Authentication for Critical Function vulnerability in Wago PFC 100 Firmware and PFC 200 Firmware
An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12).
network
low complexity
wago CWE-306
critical
9.1
2019-12-18 CVE-2019-5077 Missing Authentication for Critical Function vulnerability in Wago PFC 100 Firmware and PFC 200 Firmware
An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12).
network
low complexity
wago CWE-306
critical
9.1
2019-12-18 CVE-2019-8682 Missing Authentication for Critical Function vulnerability in Apple Iphone OS and Watchos
The issue was addressed with improved UI handling.
low complexity
apple CWE-306
2.4