Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-10-07 CVE-2022-39290 Improper Authentication vulnerability in Zoneminder
ZoneMinder is a free, open source Closed-circuit television software application.
network
low complexity
zoneminder CWE-287
6.5
2022-10-07 CVE-2022-21936 Improper Authentication vulnerability in Johnsoncontrols Metasys Extended Application and Data Server 12.0
On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.
network
low complexity
johnsoncontrols CWE-287
6.5
2022-10-06 CVE-2022-40494 Improper Authentication vulnerability in NPS Project NPS
NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.
network
low complexity
nps-project CWE-287
critical
9.8
2022-09-30 CVE-2022-20662 Improper Authentication vulnerability in Cisco DUO 1.1.0/1.1.1/2.0
A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker with physical access to bypass authentication.
low complexity
cisco CWE-287
6.8
2022-09-29 CVE-2022-39250 Improper Authentication vulnerability in Matrix Javascript SDK
Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript.
network
low complexity
matrix CWE-287
7.5
2022-09-29 CVE-2021-40693 Improper Authentication vulnerability in Moodle
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.
network
low complexity
moodle CWE-287
6.5
2022-09-28 CVE-2022-39255 Improper Authentication vulnerability in Matrix Software Development KIT
Matrix iOS SDK allows developers to build iOS apps compatible with Matrix.
network
low complexity
matrix CWE-287
7.5
2022-09-28 CVE-2022-39257 Improper Authentication vulnerability in Matrix Software Development KIT
Matrix iOS SDK allows developers to build iOS apps compatible with Matrix.
network
low complexity
matrix CWE-287
7.5
2022-09-28 CVE-2022-39263 Improper Authentication vulnerability in Nextauth.Js Next-Auth
`@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.js.
network
high complexity
nextauth-js CWE-287
8.1
2022-09-28 CVE-2022-39249 Improper Authentication vulnerability in Matrix Javascript SDK
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript.
network
low complexity
matrix CWE-287
7.5