Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2019-12-26 CVE-2019-19982 Improper Authentication vulnerability in Icegram Email Subscribers & Newsletters
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation.
network
low complexity
icegram CWE-287
5.3
2019-12-23 CVE-2019-5108 Improper Authentication vulnerability in multiple products
An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3.
6.5
2019-12-18 CVE-2019-5486 Improper Authentication vulnerability in Gitlab
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.
network
low complexity
gitlab CWE-287
8.8
2019-12-18 CVE-2019-8804 Improper Authentication vulnerability in Apple Iphone OS
An inconsistency in Wi-Fi network configuration settings was addressed.
low complexity
apple CWE-287
5.7
2019-12-18 CVE-2019-8760 Improper Authentication vulnerability in Apple Iphone OS
This issue was addressed by improving Face ID machine learning models.
low complexity
apple CWE-287
6.8
2019-12-18 CVE-2019-8704 Improper Authentication vulnerability in Apple Tvos
An authentication issue was addressed with improved state management.
local
low complexity
apple CWE-287
5.5
2019-12-18 CVE-2019-8634 Improper Authentication vulnerability in Apple mac OS X
An authentication issue was addressed with improved state management.
network
low complexity
apple CWE-287
8.8
2019-12-18 CVE-2019-8533 Improper Authentication vulnerability in Apple mac OS X
A lock handling issue was addressed with improved lock handling.
local
low complexity
apple CWE-287
7.8
2019-12-15 CVE-2014-8650 Improper Authentication vulnerability in multiple products
python-requests-Kerberos through 0.5 does not handle mutual authentication
network
low complexity
requests-kerberos-project debian CWE-287
critical
9.8
2019-12-14 CVE-2019-5252 Improper Authentication vulnerability in Huawei products
There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro).
low complexity
huawei CWE-287
3.5