Vulnerabilities > Improper Authentication

DATE CVE VULNERABILITY TITLE RISK
2021-09-30 CVE-2021-41292 Improper Authentication vulnerability in Ecoa products
ECOA BAS controller suffers from an authentication bypass vulnerability.
network
low complexity
ecoa CWE-287
critical
9.1
2021-09-29 CVE-2021-35943 Improper Authentication vulnerability in Couchbase Server
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control.
network
low complexity
couchbase CWE-287
critical
9.8
2021-09-27 CVE-2021-31606 Improper Authentication vulnerability in Openvpn-Monitor Project Openvpn-Monitor
furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
network
low complexity
openvpn-monitor-project CWE-287
7.5
2021-09-27 CVE-2021-38299 Improper Authentication vulnerability in Spomky-Labs Webauthn Framwork
Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control.
network
low complexity
spomky-labs CWE-287
critical
9.8
2021-09-24 CVE-2021-41503 Improper Authentication vulnerability in multiple products
DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control.
low complexity
dlink d-link CWE-287
8.0
2021-09-24 CVE-2021-22869 Improper Authentication vulnerability in Github Enterprise Server
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to.
network
low complexity
github CWE-287
critical
9.8
2021-09-21 CVE-2021-31917 Improper Authentication vulnerability in multiple products
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0).
network
low complexity
redhat infinispan CWE-287
critical
9.8
2021-09-17 CVE-2021-41317 Improper Authentication vulnerability in XSS Hunter Express Project XSS Hunter Express
XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.
network
low complexity
xss-hunter-express-project CWE-287
critical
9.8
2021-09-15 CVE-2021-33044 Improper Authentication vulnerability in Dahuasecurity products
The identity authentication bypass vulnerability found in some Dahua products during the login process.
network
low complexity
dahuasecurity CWE-287
critical
9.8
2021-09-15 CVE-2021-33045 Improper Authentication vulnerability in Dahuasecurity products
The identity authentication bypass vulnerability found in some Dahua products during the login process.
network
low complexity
dahuasecurity CWE-287
critical
9.8