Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
ClearanceKit's signed policy tables lack monotonic counter, allowing replay of older legitimately-signed snapshots
Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.
Misskey: TOTP tokens can be reused
Logto: TOTP code can be replayed within the RFC 6238 validity window (one-time use violation)
Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
CoreWCF: SAML token replay protection is inoperative
Gitea OAuth2 authorization codes lack expiry and reuse enforcement
Gitea TOTP single-use enforcement defect allows OTP replay
SAML Authentication Replay in Rancher
Alps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay Attack
Apache Shiro: Remember-me cookie isn't checked for expiry on the server
Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay
Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
Apache APISIX: Session replay issue in hmac-auth
Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-485 message sniffing and replay
WSS4J validation does not use configured replay cache
Showing 1 - 20 of 1,000+ results