Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-01-13 CVE-2021-34993 Improper Authentication vulnerability in Commvault Commcell 11.22.22
This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22.
network
low complexity
commvault CWE-287
critical
9.8
2022-01-13 CVE-2021-33046 Improper Authentication vulnerability in Dahuasecurity products
Some Dahua products have access control vulnerability in the password reset process.
network
low complexity
dahuasecurity CWE-287
critical
9.8
2022-01-13 CVE-2022-21684 Improper Authentication vulnerability in Discourse
Discourse is an open source discussion platform.
network
low complexity
discourse CWE-287
8.8
2022-01-13 CVE-2022-23134 Improper Authentication vulnerability in multiple products
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well.
network
low complexity
zabbix fedoraproject debian CWE-287
5.3
2022-01-11 CVE-2021-43999 Improper Authentication vulnerability in Apache Guacamole 1.2.0/1.3.0
Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider.
network
low complexity
apache CWE-287
8.8
2022-01-10 CVE-2022-22284 Improper Authentication vulnerability in Samsung Internet
Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication
local
low complexity
samsung CWE-287
5.5
2022-01-10 CVE-2022-22289 Improper Authentication vulnerability in Samsung S Assistant
Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.
network
low complexity
samsung CWE-287
5.3
2022-01-04 CVE-2021-45389 Improper Authentication vulnerability in Starwind Command Center and San&Nas
A flaw was found with the JWT token.
network
low complexity
starwind CWE-287
critical
9.8
2022-01-03 CVE-2021-45917 Improper Authentication vulnerability in SUN Moon Jingyao Network Computer Terminal Protection System Firmware
The server-request receiver function of Shockwall system has an improper authentication vulnerability.
low complexity
sun-moon-jingyao CWE-287
critical
9.0
2021-12-30 CVE-2021-20168 Improper Authentication vulnerability in Netgear Rax43 Firmware 1.0.3.96
Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface.
low complexity
netgear CWE-287
6.8