Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-07-26 CVE-2022-30270 Improper Authentication vulnerability in Motorola Ace1000 Firmware
The Motorola ACE1000 RTU through 2022-05-02 has default credentials.
network
low complexity
motorola CWE-287
critical
9.8
2022-07-26 CVE-2022-36412 Improper Authentication vulnerability in Zohocorp Manageengine Supportcenter Plus 11.0
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass.
network
low complexity
zohocorp CWE-287
critical
9.8
2022-07-25 CVE-2022-34575 Improper Authentication vulnerability in Wavlink Wifi-Repeater Firmware Rpta277W.M4300.01.Gd.2017Sep19
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing fctest.shtml.
low complexity
wavlink CWE-287
5.7
2022-07-22 CVE-2022-31164 Improper Authentication vulnerability in Tovyblox Tovy
Tovy is a a staff management system for Roblox groups.
network
low complexity
tovyblox CWE-287
7.5
2022-07-21 CVE-2022-28666 Improper Authentication vulnerability in Yikesinc Custom Product Tabs for Woocommerce
Broken Access Control vulnerability in YIKES Inc.
network
low complexity
yikesinc CWE-287
5.3
2022-07-20 CVE-2022-26136 Improper Authentication vulnerability in Atlassian products
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps.
network
low complexity
atlassian CWE-287
critical
9.8
2022-07-19 CVE-2022-34535 Improper Authentication vulnerability in DW Megapix Firmware 4.2.0.32842
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.
network
low complexity
dw CWE-287
7.5
2022-07-18 CVE-2022-30623 Improper Authentication vulnerability in Chcnav P5E Gnss Firmware 4.1/4.2
The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.
network
low complexity
chcnav CWE-287
critical
9.8
2022-07-18 CVE-2022-30624 Improper Authentication vulnerability in Chcnav P5E Gnss Firmware 4.1/4.2
Browsing the admin.html page allows the user to reset the admin password.
network
low complexity
chcnav CWE-287
7.5
2022-07-18 CVE-2021-40874 Improper Authentication vulnerability in multiple products
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13.
network
low complexity
lemonldap-ng debian CWE-287
critical
9.8