Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2019-05-29 CVE-2019-12440 Improper Authentication vulnerability in Sitecore Rocks
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.
network
low complexity
sitecore CWE-287
critical
9.8
2019-05-28 CVE-2019-12395 Improper Authentication vulnerability in Dynmap Project Dynmap
In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can see a map image without login even if victim enables login-required in setting.
network
low complexity
dynmap-project CWE-287
5.3
2019-05-24 CVE-2018-12013 Improper Authentication vulnerability in Qualcomm products
Improper authentication in locked memory region can lead to unprivilged access to the memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607, MDM9650, MDM9655, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 636, SD 712 / SD 710 / SD 670, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM630, SDM660, SXR1130
local
low complexity
qualcomm CWE-287
7.8
2019-05-24 CVE-2018-11271 Improper Authentication vulnerability in Qualcomm products
Improper authentication can happen on Remote command handling due to inappropriate handling of events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SM7150, Snapdragon_High_Med_2016, SXR1130
network
low complexity
qualcomm CWE-287
critical
9.8
2019-05-23 CVE-2019-12300 Improper Authentication vulnerability in Buildbot
Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user.
network
low complexity
buildbot CWE-287
critical
9.8
2019-05-22 CVE-2019-6814 Improper Authentication vulnerability in Schneider-Electric products
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the encoder webUI.
network
low complexity
schneider-electric CWE-287
critical
9.8
2019-05-22 CVE-2018-7847 Improper Authentication vulnerability in Schneider-Electric products
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service or potential code execution by overwriting configuration settings of the controller over Modbus.
network
low complexity
schneider-electric CWE-287
critical
9.8
2019-05-22 CVE-2019-8443 Improper Authentication vulnerability in Atlassian Jira
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.
network
high complexity
atlassian CWE-287
8.1
2019-05-16 CVE-2019-10911 Improper Authentication vulnerability in multiple products
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled.
network
high complexity
sensiolabs drupal CWE-287
7.5
2019-05-13 CVE-2019-7218 Improper Authentication vulnerability in Citrix Sharefile
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication.
network
high complexity
citrix CWE-287
5.9