Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-08-03 CVE-2022-27484 Improper Authentication vulnerability in Fortinet Fortiadc
A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticated attacker to bypass the Old Password check in the password change form via a crafted HTTP request.
network
low complexity
fortinet CWE-287
4.3
2022-07-26 CVE-2022-30270 Improper Authentication vulnerability in Motorola Ace1000 Firmware
The Motorola ACE1000 RTU through 2022-05-02 has default credentials.
network
low complexity
motorola CWE-287
critical
9.8
2022-07-26 CVE-2022-36412 Improper Authentication vulnerability in Zohocorp Manageengine Supportcenter Plus 11.0
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass.
network
low complexity
zohocorp CWE-287
critical
9.8
2022-07-25 CVE-2022-34575 Improper Authentication vulnerability in Wavlink Wifi-Repeater Firmware Rpta277W.M4300.01.Gd.2017Sep19
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing fctest.shtml.
low complexity
wavlink CWE-287
5.7
2022-07-20 CVE-2022-26136 Improper Authentication vulnerability in Atlassian products
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps.
network
low complexity
atlassian CWE-287
critical
9.8
2022-07-19 CVE-2022-34535 Improper Authentication vulnerability in DW Megapix Firmware 4.2.0.32842
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.
network
low complexity
dw CWE-287
7.5
2022-07-18 CVE-2022-30623 Improper Authentication vulnerability in Chcnav P5E Gnss Firmware 4.1/4.2
The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.
network
low complexity
chcnav CWE-287
critical
9.8
2022-07-18 CVE-2022-30624 Improper Authentication vulnerability in Chcnav P5E Gnss Firmware 4.1/4.2
Browsing the admin.html page allows the user to reset the admin password.
network
low complexity
chcnav CWE-287
7.5
2022-07-18 CVE-2021-40874 Improper Authentication vulnerability in multiple products
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13.
network
low complexity
lemonldap-ng debian CWE-287
critical
9.8
2022-07-17 CVE-2022-30550 Improper Authentication vulnerability in multiple products
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20.
network
low complexity
dovecot debian CWE-287
8.8