Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-09-08 CVE-2022-38399 Improper Authentication vulnerability in Planex Cs-Qr10 Firmware and Cs-Qr20 Firmware
Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection
low complexity
planex CWE-287
6.8
2022-09-07 CVE-2022-36073 Improper Authentication vulnerability in Rubygems
RubyGems.org is the Ruby community gem host.
network
low complexity
rubygems CWE-287
8.8
2022-09-07 CVE-2022-3152 Improper Authentication vulnerability in PHP-Fusion PHPfusion
Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.
network
low complexity
php-fusion CWE-287
8.8
2022-09-06 CVE-2022-26858 Improper Authentication vulnerability in Dell products
Dell BIOS versions contain an Improper Authentication vulnerability.
local
low complexity
dell CWE-287
7.8
2022-09-01 CVE-2022-34372 Improper Authentication vulnerability in Dell Powerprotect Cyber Recovery
Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability.
network
low complexity
dell CWE-287
critical
9.1
2022-09-01 CVE-2022-34379 Improper Authentication vulnerability in Dell Cloudlink
Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability.
network
low complexity
dell CWE-287
critical
9.8
2022-09-01 CVE-2022-34380 Improper Authentication vulnerability in Dell Cloudlink
Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability.
local
low complexity
dell CWE-287
8.2
2022-08-28 CVE-2022-36755 Improper Authentication vulnerability in Dlink Dir-845L Firmware
D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.
network
low complexity
dlink CWE-287
critical
9.8
2022-08-28 CVE-2022-38556 Improper Authentication vulnerability in Trendnet Tew733Gr Firmware 1.03B01
Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
network
low complexity
trendnet CWE-287
critical
9.8
2022-08-28 CVE-2022-38557 Improper Authentication vulnerability in Dlink Dir-845L Firmware
D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
network
low complexity
dlink CWE-287
critical
9.8