Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
Apache Kerby: Kerberos Pre-Authentication Bypass
ChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2
Termix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTP
Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication ve...
Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamer
Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TO...
An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110
LinkJoin through 882f196 mishandles token ownership in password reset
A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 throu...
Signal App Biometric Authentication missing critical step in authentication
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
Authentication Bypass in gaizhenbiao/ChuanhuChatGPT
IDOR Vulnerability in transformeroptimus/superagi
Authentication Bypass in composiohq/composio
Missing check_access in lollms_binding_infos in parisneo/lollms
Improper Access Control in Elfatek Elektronics' ANKA JPD-00028
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability
Multi-Factor Authentication Bypass in Progress WS_FTP Server
Showing 1 - 20 of 1,000+ results