Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-12-06 CVE-2022-38336 Improper Authentication vulnerability in Mobatek Mobaxterm
An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.
network
high complexity
mobatek CWE-287
8.1
2022-12-05 CVE-2022-40242 Improper Authentication vulnerability in AMI Megarac Sp-X 12/13
MegaRAC Default Credentials Vulnerability
network
low complexity
ami CWE-287
critical
9.8
2022-12-05 CVE-2022-40259 Improper Authentication vulnerability in AMI Megarac Sp-X 12/13
MegaRAC Default Credentials Vulnerability
network
low complexity
ami CWE-287
critical
9.8
2022-12-05 CVE-2022-43549 Improper Authentication vulnerability in Veeam Backup for Google Cloud 1.0/3.0
Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.
network
low complexity
veeam CWE-287
critical
9.8
2022-12-05 CVE-2022-43557 Improper Authentication vulnerability in BD products
The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface.
high complexity
bd CWE-287
5.3
2022-12-05 CVE-2022-43504 Improper Authentication vulnerability in Wordpress
Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature.
network
low complexity
wordpress CWE-287
5.3
2022-12-04 CVE-2022-46411 Improper Authentication vulnerability in Veritas Access Appliance and Netbackup Flex Scale Appliance
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100.
network
low complexity
veritas CWE-287
8.8
2022-12-01 CVE-2022-43900 Improper Authentication vulnerability in IBM Websphere Automation for IBM Cloud PAK for Watson Aiops 1.4.2
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security.
local
low complexity
ibm CWE-287
6.5
2022-11-28 CVE-2021-45036 Improper Authentication vulnerability in Velneo Vclient 28.1.3
Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.
network
high complexity
velneo CWE-287
7.4
2022-11-23 CVE-2022-37774 Improper Authentication vulnerability in Maarch RM
There is a broken access control vulnerability in the Maarch RM 2.8.3 solution.
network
low complexity
maarch CWE-287
5.3