Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2025-03-17 CVE-2025-2388 A vulnerability was found in Keytop ???????? 2.7.1.
network
low complexity
CWE-287
7.3
2025-03-11 CVE-2024-56336 A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0 or SZVSN and the FS number is 02).
network
low complexity
CWE-287
critical
9.8
2025-03-08 CVE-2024-11087 Improper Authentication vulnerability in Miniorange Social Login
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9.
network
low complexity
miniorange CWE-287
critical
9.8
2025-03-07 CVE-2025-1475 The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5.
network
low complexity
CWE-287
critical
9.8
2025-03-03 CVE-2024-38426 Improper Authentication vulnerability in Qualcomm products
While processing the authentication message in UE, improper authentication may lead to information disclosure.
network
low complexity
qualcomm CWE-287
5.3
2025-02-24 CVE-2025-27112 Improper Authentication vulnerability in Navidrome
Navidrome is an open source web-based music collection server and streamer.
network
low complexity
navidrome CWE-287
6.5
2025-02-04 CVE-2025-0890 **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
network
low complexity
CWE-287
critical
9.8
2025-01-08 CVE-2023-52955 Improper Authentication vulnerability in Huawei Emui and Harmonyos
Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
network
low complexity
huawei CWE-287
7.5
2025-01-08 CVE-2024-56445 Improper Authentication vulnerability in Huawei Harmonyos 5.0.0
Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
network
low complexity
huawei CWE-287
5.3
2025-01-07 CVE-2024-12264 The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3.
network
low complexity
CWE-287
critical
9.8