Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-10-18 CVE-2022-31122 Improper Authentication vulnerability in Wire Server
Wire is an encrypted communication and collaboration platform.
network
high complexity
wire CWE-287
8.1
2022-10-18 CVE-2022-22237 Improper Authentication vulnerability in Juniper Junos
An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause an impact on confidentiality or integrity.
network
low complexity
juniper CWE-287
6.5
2022-10-17 CVE-2022-23769 Improper Authentication vulnerability in Megazone Reversewall-Mds 3.8A007
Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS.
network
low complexity
megazone CWE-287
critical
9.8
2022-10-17 CVE-2022-2533 Improper Authentication vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2.
network
high complexity
gitlab CWE-287
7.4
2022-10-14 CVE-2022-41436 Improper Authentication vulnerability in Oxhoo Tp50 Firmware Oxh1.50
An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the URL http://device_ip/index1.html.
network
low complexity
oxhoo CWE-287
critical
9.1
2022-10-14 CVE-2022-42463 Improper Authentication vulnerability in Openharmony 3.1/3.1.1/3.1.2
OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem.
low complexity
openharmony CWE-287
8.8
2022-10-13 CVE-2022-35135 Improper Authentication vulnerability in Boodskap IOT Platform 4.4.902
Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<uuid>.
network
low complexity
boodskap CWE-287
8.8
2022-10-13 CVE-2022-39229 Improper Authentication vulnerability in Grafana
Grafana is an open source data visualization platform for metrics, logs, and traces.
network
low complexity
grafana CWE-287
4.3
2022-10-12 CVE-2021-36369 Improper Authentication vulnerability in multiple products
An issue was discovered in Dropbear through 2020.81.
network
low complexity
dropbear-ssh-project debian CWE-287
7.5
2022-10-12 CVE-2022-40664 Improper Authentication vulnerability in Apache Shiro
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
network
low complexity
apache CWE-287
critical
9.8