Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-08-18 CVE-2022-22730 Improper Authentication vulnerability in Intel Edge Insights for Industrial
Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
network
low complexity
intel CWE-287
critical
9.8
2022-08-18 CVE-2022-35198 Improper Authentication vulnerability in Contract Management System Project Contract Managment System 2.0
Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.
7.5
2022-08-15 CVE-2022-38368 Improper Authentication vulnerability in Aviatrix Gateway
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376.
network
low complexity
aviatrix CWE-287
8.8
2022-08-15 CVE-2022-36524 Improper Authentication vulnerability in Dlink Go-Rt-Ac750 Firmware 101B03/200B02
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.
network
low complexity
dlink CWE-287
7.5
2022-08-12 CVE-2022-37397 Improper Authentication vulnerability in Yugabyte Yugabytedb 2.6.1
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory.
network
low complexity
yugabyte CWE-287
critical
9.8
2022-08-12 CVE-2022-2503 Improper Authentication vulnerability in Linux Kernel
Dm-verity is used for extending root-of-trust to root filesystems.
local
low complexity
linux CWE-287
6.7
2022-08-12 CVE-2022-38180 Improper Authentication vulnerability in Jetbrains Ktor
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
network
low complexity
jetbrains CWE-287
6.5
2022-08-10 CVE-2022-32429 Improper Authentication vulnerability in Megatech Msnswitch Firmware Mnt.2408
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.
network
low complexity
megatech CWE-287
critical
9.8
2022-08-09 CVE-2022-29083 Improper Authentication vulnerability in Dell products
Prior Dell BIOS versions contain an Improper Authentication vulnerability.
low complexity
dell CWE-287
6.8
2022-08-05 CVE-2022-2303 Improper Authentication vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1.
network
low complexity
gitlab CWE-287
4.3