Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
Capgo - Insufficient Authentication in Email Change Endpoint
H3C NX15 Administrator Password Modification Endpoint modify change_passwd password recovery
Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection
SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
Missing Authentication
Weak Password Recovery Mechanism in Portal for ArcGIS
Coolify: Password reset link poisoning via X-Forwarded-Host header spoofing
FOSSBilling: Client password reset token reuse allows persistent account takeover
Account Denial of Service in MCO
Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter
SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account T...
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
Cap-go - Account Lockout via 2FA Misconfiguration on Unverified Email
Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation
PbootCMS Password MemberController.php retrieve password recovery
LimeSurvey Password Reset Host Header Injection Discloses Reset Token
OUSL-GROUP-BrinaryBrains School Student Management System Forgot Password Endpoint Login.php ajax_forgot_password password recovery
Simple History – Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Subscriber+) Account Takeover via Missing Authorization on Even...
Showing 1 - 20 of 1,000+ results