Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2019-11-12 CVE-2019-17235 Missing Authentication for Critical Function vulnerability in Getigniteup Igniteup
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
network
low complexity
getigniteup CWE-306
5.3
2019-11-12 CVE-2019-17234 Missing Authentication for Critical Function vulnerability in Getigniteup Igniteup
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.
network
low complexity
getigniteup CWE-306
7.5
2019-11-06 CVE-2019-5644 Missing Authentication for Critical Function vulnerability in Gatech Computing for Good'S Basic Laboratory Information System 3.3/3.4/3.5
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter several facets of a user account, including promoting any user to an administrator.
network
low complexity
gatech CWE-306
critical
9.8
2019-11-06 CVE-2019-5643 Missing Authentication for Critical Function vulnerability in Gatech Computing for Good'S Basic Laboratory Information System 3.3/3.4/3.5
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may enumerate the user names and facility names in use on a particular installation.
network
low complexity
gatech CWE-306
5.3
2019-11-06 CVE-2019-5617 Missing Authentication for Critical Function vulnerability in Gatech Computing for Good'S Basic Laboratory Information System 3.3/3.4
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may change the password of any administrator-level user.
network
low complexity
gatech CWE-306
critical
9.8
2019-11-06 CVE-2006-0062 Missing Authentication for Critical Function vulnerability in Sillycycle Xlockmore 5.13
xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.
network
low complexity
sillycycle CWE-306
critical
9.8
2019-11-06 CVE-2006-0061 Missing Authentication for Critical Function vulnerability in Sillycycle Xlockmore 5.13/5.22
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession.
network
low complexity
sillycycle CWE-306
critical
9.8
2019-10-31 CVE-2019-18230 Missing Authentication for Critical Function vulnerability in Honeywell products
Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.
network
low complexity
honeywell CWE-306
7.5
2019-10-31 CVE-2019-13547 Missing Authentication for Critical Function vulnerability in Advantech Wise-Paas/Rmm 3.3.29
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior.
network
low complexity
advantech CWE-306
critical
9.8
2019-10-31 CVE-2019-18465 Missing Authentication for Critical Function vulnerability in Ipswitch Moveit Transfer 11.1/11.1.1
In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface.
network
low complexity
ipswitch CWE-306
critical
9.8