Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2020-02-11 CVE-2013-1360 Improper Authentication vulnerability in Sonicwall products
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.
network
low complexity
sonicwall CWE-287
critical
9.8
2020-02-11 CVE-2014-8347 Improper Authentication vulnerability in Claris Filemaker PRO and Filemaker PRO Advanced
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges.
local
low complexity
claris CWE-287
7.8
2020-02-10 CVE-2019-6744 Improper Authentication vulnerability in Samsung Knox 1.2.02.39
This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder.
low complexity
samsung CWE-287
4.3
2020-02-10 CVE-2019-20062 Improper Authentication vulnerability in Mfscripts Yetishare
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).
network
low complexity
mfscripts CWE-287
critical
9.8
2020-02-10 CVE-2017-18641 Improper Authentication vulnerability in Linuxcontainers LXC 2.0.0
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
network
high complexity
linuxcontainers CWE-287
8.1
2020-02-07 CVE-2013-3096 Improper Authentication vulnerability in Dlink Dir865L Firmware 1.03
D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.
network
high complexity
dlink CWE-287
5.9
2020-02-07 CVE-2013-3091 Improper Authentication vulnerability in Belkin N300 Firmware 1.00.06
An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."
network
low complexity
belkin CWE-287
critical
9.8
2020-02-06 CVE-2012-6340 Improper Authentication vulnerability in Netgear Wgr614V7 Firmware and Wgr614V9 Firmware
An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial programming, a related issue to CVE-2006-1002.
low complexity
netgear CWE-287
4.6
2020-02-06 CVE-2020-8771 Improper Authentication vulnerability in Wptimecapsule WP Time Capsule
The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass.
network
low complexity
wptimecapsule CWE-287
critical
9.8
2020-02-05 CVE-2013-2681 Improper Authentication vulnerability in Cisco Linksys E4200 Firmware 1.0.05
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.
network
low complexity
cisco CWE-287
critical
9.8