Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2023-05-08 CVE-2023-28182 Improper Authentication vulnerability in Apple Iphone OS and Macos
The issue was addressed with improved authentication.
network
low complexity
apple CWE-287
6.5
2023-05-04 CVE-2023-21484 Improper Authentication vulnerability in Samsung Android 11.0/12.0/13.0
Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation.
local
low complexity
samsung CWE-287
7.8
2023-05-04 CVE-2023-21487 Improper Authentication vulnerability in Samsung Android 11.0/12.0/13.0
Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.
local
low complexity
samsung CWE-287
3.3
2023-05-04 CVE-2023-30328 Improper Authentication vulnerability in Mailbutler Shimo 5.0.4
An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use.
network
low complexity
mailbutler CWE-287
critical
9.8
2023-05-03 CVE-2022-45860 Improper Authentication vulnerability in Fortinet Fortinac and Fortinac-F
A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.
network
low complexity
fortinet CWE-287
7.5
2023-05-03 CVE-2022-30995 Improper Authentication vulnerability in Acronis Cyber Backup and Cyber Protect
Sensitive information disclosure due to improper authentication.
network
low complexity
acronis CWE-287
7.5
2023-05-02 CVE-2023-30869 Improper Authentication vulnerability in Sandhillsdev Easy Digital Downloads
Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth.
network
low complexity
sandhillsdev CWE-287
critical
9.8
2023-05-01 CVE-2022-35898 Improper Authentication vulnerability in Opentext Bizmanager
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation.
network
low complexity
opentext CWE-287
critical
9.8
2023-05-01 CVE-2023-30061 Improper Authentication vulnerability in Dlink Dir-879 Firmware 1.10
D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.
network
low complexity
dlink CWE-287
7.5
2023-05-01 CVE-2023-30063 Improper Authentication vulnerability in Dlink Dir-890L Firmware 1.05
D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.
network
low complexity
dlink CWE-287
7.5