Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2024-09-17 CVE-2024-8956 Improper Authentication vulnerability in Ptzoptics Pt30X-Ndi-Xx-G2 Firmware and Pt30X-Sdi Firmware
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue.
network
low complexity
ptzoptics CWE-287
critical
9.1
2024-09-17 CVE-2024-44202 Improper Authentication vulnerability in Apple Iphone OS
An authentication issue was addressed with improved state management.
network
low complexity
apple CWE-287
5.3
2024-09-13 CVE-2024-45113 Improper Authentication vulnerability in Adobe Coldfusion 2021/2023
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation.
network
low complexity
adobe CWE-287
7.5
2024-09-11 CVE-2024-8642 Improper Authentication vulnerability in Eclipse Dataspace Components
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for token expiration.
network
low complexity
eclipse CWE-287
8.1
2024-09-06 CVE-2023-45038 Improper Authentication vulnerability in Qnap Music Station
An improper authentication vulnerability has been reported to affect Music Station.
network
low complexity
qnap CWE-287
8.8
2024-09-05 CVE-2024-5956 Improper Authentication vulnerability in Trellix Intrusion Prevention System Manager 11.1.7.97
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly
network
low complexity
trellix CWE-287
5.3
2024-09-05 CVE-2024-5957 Improper Authentication vulnerability in Trellix Intrusion Prevention System Manager 10.1
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
network
low complexity
trellix CWE-287
7.5
2024-09-04 CVE-2024-7012 Improper Authentication vulnerability in Redhat Satellite 6.13/6.14/6.15
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration.
network
low complexity
redhat CWE-287
critical
9.8
2024-09-04 CVE-2024-7870 Improper Authentication vulnerability in Pixelyoursite
The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.7.1 and 10.4.2, respectively, through publicly exposed log files.
network
low complexity
pixelyoursite CWE-287
7.5
2024-09-03 CVE-2024-7346 Improper Authentication vulnerability in Progress Openedge
Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection.  This has been corrected so that default certificates are no longer capable of overriding host name validation and will need to be replaced where full TLS certificate validation is needed for network security.  The existing certificates should be replaced with CA-signed certificates from a recognized certificate authority that contain the necessary information to support host name validation.
network
high complexity
progress CWE-287
4.8