Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2019-07-30 CVE-2019-5455 Improper Authentication vulnerability in Nextcloud 3.6.0
Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.
low complexity
nextcloud CWE-287
6.8
2019-07-30 CVE-2019-5453 Improper Authentication vulnerability in Nextcloud
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.
low complexity
nextcloud CWE-287
6.1
2019-07-30 CVE-2019-11202 Improper Authentication vulnerability in Suse Rancher
An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1.
network
low complexity
suse CWE-287
critical
9.8
2019-07-29 CVE-2018-17213 Improper Authentication vulnerability in Printeron Central Print Services 2.5/4.1.4
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4.
network
low complexity
printeron CWE-287
8.8
2019-07-29 CVE-2019-1020018 Improper Authentication vulnerability in Discourse
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
network
low complexity
discourse CWE-287
7.3
2019-07-22 CVE-2018-13927 Improper Authentication vulnerability in Qualcomm products
Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, SD 410/12, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SXR1130
local
low complexity
qualcomm CWE-287
7.8
2019-07-19 CVE-2015-7882 Improper Authentication vulnerability in Mongodb 3.0.0/3.0.6
Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.
network
high complexity
mongodb CWE-287
8.1
2019-07-17 CVE-2019-1917 Improper Authentication vulnerability in Cisco Vision Dynamic Signage Director
A vulnerability in the REST API interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentication on an affected system.
network
low complexity
cisco CWE-287
critical
9.8
2019-07-11 CVE-2018-18095 Improper Authentication vulnerability in Intel SSD DC S4500 Firmware and SSD DC S4600 Firmware
Improper authentication in firmware for Intel(R) SSD DC S4500 Series and Intel(R) SSD DC S4600 Series before SCV10150 may allow an unprivileged user to potentially enable escalation of privilege via physical access.
low complexity
intel CWE-287
6.8
2019-07-10 CVE-2019-10966 Improper Authentication vulnerability in GE products
In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.
network
low complexity
ge CWE-287
5.3