Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
Apache Shiro: Authentication bypass in Guice-Web integration
Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
Rsync < 3.4.3 Authorization Bypass via Hostname Resolution
Util-linux: util-linux: access control bypass due to improper hostname canonicalization
OpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channels
Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems
Soft Serve has Critical Authentication Bypass
Keycloak: keycloak idor in realm client creating/deleting
Elated Membership <= 1.2 - Authentication Bypass via Social Login
authentik deactivated service accounts can authenticate to OAuth
(conda) Constructor: Excessive permissions during and after installation
Cryostat: authentication bypass if network policies are disabled
Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running ...
WP JobHunt <= 7.1 - Authentication Bypass to Candidate
DataEase has an unauthorized vulnerability
Drupal core - Moderately critical - Access bypass - SA-CORE-2024-004
Symphony has an Authentication Bypass via RememberMe
Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary
Showing 1 - 20 of 1,000+ results