Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2019-06-11 CVE-2019-3411 Missing Authentication for Critical Function vulnerability in ZTE Mf920 Firmware
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability.
network
low complexity
zte CWE-306
7.5
2019-06-10 CVE-2019-9881 Missing Authentication for Critical Function vulnerability in Wpengine Wpgraphql 0.2.3
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.
network
low complexity
wpengine CWE-306
5.3
2019-06-10 CVE-2019-9880 Missing Authentication for Critical Function vulnerability in Wpengine Wpgraphql 0.2.3
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress.
network
low complexity
wpengine CWE-306
critical
9.1
2019-06-10 CVE-2019-9879 Missing Authentication for Critical Function vulnerability in Wpengine Wpgraphql 0.2.3
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed.
network
low complexity
wpengine CWE-306
critical
9.8
2019-06-06 CVE-2019-6451 Missing Authentication for Critical Function vulnerability in Soyal Ar-727H Firmware and Ar-829Ev5 Firmware
On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST access.
network
low complexity
soyal CWE-306
7.5
2019-05-31 CVE-2019-9105 Missing Authentication for Critical Function vulnerability in Saet Tebe Small Firmware and Webapp
The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of API calls without authentication, as demonstrated by retrieving password hashes via an inc/utils/REST_API.php?command=CallAPI&customurl=alladminusers call.
network
low complexity
saet CWE-306
7.5
2019-05-31 CVE-2019-10046 Missing Authentication for Critical Function vulnerability in Pydio 8.2.2
An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information.
network
low complexity
pydio CWE-306
5.3
2019-05-31 CVE-2019-9871 Missing Authentication for Critical Function vulnerability in Jector Fm-K75 Firmware
Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission.
network
low complexity
jector CWE-306
critical
9.8
2019-05-31 CVE-2019-12500 Missing Authentication for Critical Function vulnerability in MI M365 Firmware
The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands.
low complexity
mi CWE-306
6.5
2019-05-29 CVE-2019-6958 Missing Authentication for Critical Function vulnerability in Bosch products
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC) and Video SDK (VSDK).
network
low complexity
bosch CWE-306
critical
9.1