Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-09-09 CVE-2022-38081 Improper Authentication vulnerability in Openharmony 3.1/3.1.1/3.1.2
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability.
local
low complexity
openharmony CWE-287
5.5
2022-09-09 CVE-2022-38700 Improper Authentication vulnerability in Openharmony 3.1.1
OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability.
low complexity
openharmony CWE-287
8.8
2022-09-08 CVE-2022-36092 Improper Authentication vulnerability in Xwiki
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform.
network
low complexity
xwiki CWE-287
7.5
2022-09-08 CVE-2022-36093 Improper Authentication vulnerability in Xwiki
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform.
network
low complexity
xwiki CWE-287
7.1
2022-09-08 CVE-2022-20923 Improper Authentication vulnerability in Cisco products
A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to bypass authentication controls and access the IPSec VPN network.
network
low complexity
cisco CWE-287
critical
9.8
2022-09-08 CVE-2022-38399 Improper Authentication vulnerability in Planex Cs-Qr10 Firmware and Cs-Qr20 Firmware
Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection
low complexity
planex CWE-287
6.8
2022-09-07 CVE-2022-36073 Improper Authentication vulnerability in Rubygems
RubyGems.org is the Ruby community gem host.
network
low complexity
rubygems CWE-287
8.8
2022-09-07 CVE-2022-3152 Improper Authentication vulnerability in PHP-Fusion PHPfusion
Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.
network
low complexity
php-fusion CWE-287
8.8
2022-09-06 CVE-2022-26858 Improper Authentication vulnerability in Dell products
Dell BIOS versions contain an Improper Authentication vulnerability.
local
low complexity
dell CWE-287
7.8
2022-09-01 CVE-2022-34372 Improper Authentication vulnerability in Dell Powerprotect Cyber Recovery
Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability.
network
low complexity
dell CWE-287
critical
9.1