Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2022-01-10 CVE-2022-22284 Improper Authentication vulnerability in Samsung Internet
Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication
local
low complexity
samsung CWE-287
5.5
2022-01-10 CVE-2022-22289 Improper Authentication vulnerability in Samsung S Assistant
Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.
network
low complexity
samsung CWE-287
5.3
2022-01-04 CVE-2021-45389 Improper Authentication vulnerability in Starwind Command Center and San&Nas
A flaw was found with the JWT token.
network
low complexity
starwind CWE-287
critical
9.8
2022-01-03 CVE-2021-45917 Improper Authentication vulnerability in SUN Moon Jingyao Network Computer Terminal Protection System Firmware
The server-request receiver function of Shockwall system has an improper authentication vulnerability.
low complexity
sun-moon-jingyao CWE-287
critical
9.0
2021-12-30 CVE-2021-20168 Improper Authentication vulnerability in Netgear Rax43 Firmware 1.0.3.96
Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface.
low complexity
netgear CWE-287
6.8
2021-12-30 CVE-2021-23147 Improper Authentication vulnerability in Netgear R6700 Firmware 1.0.4.120
Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console.
low complexity
netgear CWE-287
6.8
2021-12-30 CVE-2021-45379 Improper Authentication vulnerability in Glewlwyd Project Glewlwyd
Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability.
network
low complexity
glewlwyd-project CWE-287
8.8
2021-12-27 CVE-2021-45890 Improper Authentication vulnerability in Authguard Project Authguard
basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier.
network
low complexity
authguard-project CWE-287
critical
9.8
2021-12-22 CVE-2021-21902 Improper Authentication vulnerability in Garrett IC Module CMA 5.0
An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Module CMA Version 5.0.
network
high complexity
garrett CWE-287
8.1
2021-12-22 CVE-2021-21952 Improper Authentication vulnerability in Anker Eufy Homebase 2 Firmware 2.1.6.9H
An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h.
network
low complexity
anker CWE-287
critical
9.8