Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-12-09 CVE-2021-43068 Improper Authentication vulnerability in Fortinet Fortiauthenticator 6.4.0
A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal.
network
low complexity
fortinet CWE-287
8.1
2021-12-08 CVE-2021-36718 Improper Authentication vulnerability in Synel Eharmonynew and Synel Reports
SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The vulnerabilety has been addressed and fixed on version 11.
network
low complexity
synel CWE-287
6.5
2021-12-08 CVE-2021-37054 Improper Authentication vulnerability in Huawei Emui, Harmonyos and Magic UI
There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
network
low complexity
huawei CWE-287
7.5
2021-12-08 CVE-2021-41309 Improper Authentication vulnerability in Atlassian Jira Software Data Center
Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs of another user's Jira Service Management project via a Broken Authentication vulnerability in the /plugins/servlet/audit/resource endpoint.
network
low complexity
atlassian CWE-287
5.3
2021-12-08 CVE-2021-41311 Improper Authentication vulnerability in Atlassian Jira Software Data Center
Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint.
network
low complexity
atlassian CWE-287
7.5
2021-12-07 CVE-2021-41716 Improper Authentication vulnerability in Mahadiscom Mahavitaran 7.50
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
network
low complexity
mahadiscom CWE-287
critical
9.8
2021-12-07 CVE-2021-43175 Improper Authentication vulnerability in Goautodial and Goautodial API
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions.
network
low complexity
goautodial CWE-287
7.5
2021-12-07 CVE-2021-37043 Improper Authentication vulnerability in Huawei Emui, Harmonyos and Magic UI
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious application processes occupy system resources.
network
low complexity
huawei CWE-287
7.5
2021-12-07 CVE-2021-37100 Improper Authentication vulnerability in Huawei Harmonyos
There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authentication bypassed.
network
low complexity
huawei CWE-287
7.5
2021-12-06 CVE-2021-39890 Improper Authentication vulnerability in Gitlab
It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.
network
low complexity
gitlab CWE-287
critical
9.8