Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-11-16 CVE-2021-37580 Improper Authentication vulnerability in Apache Shenyu 2.3.0/2.4.0
A flaw was found in Apache ShenYu Admin.
network
low complexity
apache CWE-287
critical
9.8
2021-11-12 CVE-2021-3519 Improper Authentication vulnerability in Lenovo products
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
low complexity
lenovo CWE-287
6.8
2021-11-12 CVE-2021-3788 Improper Authentication vulnerability in Binatoneglobal products
An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device.
low complexity
binatoneglobal CWE-287
6.8
2021-11-09 CVE-2021-43203 Improper Authentication vulnerability in Jetbrains Ktor
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
network
low complexity
jetbrains CWE-287
7.5
2021-11-08 CVE-2021-31602 Improper Authentication vulnerability in Hitachi products
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x.
network
low complexity
hitachi CWE-287
7.5
2021-11-08 CVE-2021-42072 Improper Authentication vulnerability in multiple products
An issue was discovered in Barrier before 2.4.0.
network
low complexity
barrier-project fedoraproject CWE-287
8.8
2021-11-07 CVE-2021-43414 Improper Authentication vulnerability in GNU Hurd
An issue was discovered in GNU Hurd before 0.9 20210404-9.
local
high complexity
gnu CWE-287
7.0
2021-11-05 CVE-2021-42837 Improper Authentication vulnerability in Talend Data Catalog
An issue was discovered in Talend Data Catalog before 7.3-20210930.
network
low complexity
talend CWE-287
critical
9.8
2021-11-05 CVE-2021-25505 Improper Authentication vulnerability in Samsung Pass
Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.
local
low complexity
samsung CWE-287
7.8
2021-11-03 CVE-2021-38161 Improper Authentication vulnerability in multiple products
Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle attacks.
network
high complexity
apache debian CWE-287
8.1