Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint
Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost
Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability
Unauthenticated command injection in Control-M/Server communication command
Rancher Privilege Escalation from Project Owner to Host
Authentication Bypass for SafeLine SL6 and SL6+
Freelance Security Lock – Access to Windows OS
OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
Keycloak: keycloak: brute-force protection bypass in ciba flow
Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge...
Missing exit out of permission check in haveged could lead to root exploit
OAuth authorization code client binding not enforced during token redemption in Mattermost
Authentication Bypass in mlflow/mlflow
Aap-controller: aap-gateway: account hijacking and unauthorized access via unverified email linking
Improper Authentication vulnerability in Progress MOVEit Automation
ChurchCRM: Authentication Bypass in `/api/public/user/login` Allows Bypass of 2FA and Account Lockout
Cryptomator Hub OAuth token exchange HTTP downgrade via getAuthority() scheme confusion (CVE-2026-32303 bypass)
Cisco Secure Web Appliance Authentication Service Traffic Bypass Vulnerability
A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1
Pachno 1.0.6 Open Redirection via return_to Parameter
Showing 1 - 20 of 1,000+ results