Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-08-23 CVE-2022-35203 Improper Authentication vulnerability in Trendnet Tv-Ip572Pi Firmware 1.0
An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.
network
low complexity
trendnet CWE-287
7.2
2022-08-23 CVE-2022-34919 Improper Authentication vulnerability in Zengenti Contensis
The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated.
network
low complexity
zengenti CWE-287
critical
9.8
2022-08-22 CVE-2022-32282 Improper Authentication vulnerability in Wwbn Avideo 11.6
An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.
network
low complexity
wwbn CWE-287
8.8
2022-08-18 CVE-2022-22730 Improper Authentication vulnerability in Intel Edge Insights for Industrial
Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
network
low complexity
intel CWE-287
critical
9.8
2022-08-18 CVE-2022-35198 Improper Authentication vulnerability in Contract Management System Project Contract Managment System 2.0
Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.
7.5
2022-08-17 CVE-2022-2336 Improper Authentication vulnerability in Softing products
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`.
network
low complexity
softing CWE-287
critical
9.8
2022-08-15 CVE-2022-38368 Improper Authentication vulnerability in Aviatrix Gateway
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376.
network
low complexity
aviatrix CWE-287
8.8
2022-08-15 CVE-2022-36524 Improper Authentication vulnerability in Dlink Go-Rt-Ac750 Firmware 101B03/200B02
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.
network
low complexity
dlink CWE-287
7.5
2022-08-12 CVE-2022-37397 Improper Authentication vulnerability in Yugabyte Yugabytedb 2.6.1
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory.
network
low complexity
yugabyte CWE-287
critical
9.8
2022-08-12 CVE-2022-2503 Improper Authentication vulnerability in Linux Kernel
Dm-verity is used for extending root-of-trust to root filesystems.
local
low complexity
linux CWE-287
6.7