Show filters
692 Total Results
Displaying 41-50 of 692
Sort by:
Attacker Value
Unknown

CVE-2021-39064

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console. IBM X-Force ID: 214957.
Attacker Value
Unknown

CVE-2021-38688

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability in the following versions of Qfile: Qfile 3.0.0.1105 and later
Attacker Value
Unknown

CVE-2021-44514

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
Attacker Value
Unknown

CVE-2021-41265

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. This only affects non database authentication types and new REST API endpoints. Users should upgrade to Flask-AppBuilder 3.3.4 to receive a patch.
Attacker Value
Unknown

CVE-2021-43935

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges.
Attacker Value
Unknown

CVE-2021-21955

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.
Attacker Value
Unknown

CVE-2021-20145

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims' devices as though they were on an adjacent network.
Attacker Value
Unknown

CVE-2021-43068

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal.
Attacker Value
Unknown

CVE-2021-36718

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The vulnerabilety has been addressed and fixed on version 11. Default credentials , Security miscommunication , Sensetive data exposure vulnerability in Synel Reports of SYNEL eharmonynew, Synel Reports allows an attacker to log into the system with default credentials. This issue affects: SYNEL eharmonynew, Synel Reports 8.0.2 version 11 and prior versions.
Attacker Value
Unknown

CVE-2021-37054

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.