Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
oauth vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2023-30528
Jenkins WSO2 Oauth Plugin 1.0 and previous versions does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for malicious users to observe and capture it.
Jenkins Wso2 Oauth
4.3
CVSSv3
CVE-2022-4148
The WP OAuth Server (OAuth Authentication) WordPress plugin prior to 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
Dash10 Oauth Server
7.8
CVSSv3
CVE-2019-10460
Jenkins Bitbucket OAuth Plugin 0.9 and previous versions stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Jenkins Bitbucket Oauth
9.6
CVSSv3
CVE-2023-45144
com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and ...
Xwiki Oauth Identity
6.5
CVSSv3
CVE-2022-3632
The OAuth Client by DigitialPixies WordPress plugin up to and including 1.1.0 does not have CSRF checks in some places, which could allow malicious users to make logged-in users perform unwanted actions.
Digitialpixies Oauth Client
9.8
CVSSv3
CVE-2015-9435
The oauth2-provider plugin prior to 3.1.5 for WordPress has incorrect generation of random numbers.
Dash10 Oauth Server
4.8
CVSSv3
CVE-2022-3631
The OAuth Client by DigitialPixies WordPress plugin up to and including 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall...
Digitialpixies Oauth Client
6.1
CVSSv3
CVE-2019-10372
An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and previous versions in GitLabSecurityRealm.java allows malicious users to redirect users to a URL outside Jenkins after successful login.
Jenkins Gitlab Oauth
5.4
CVSSv3
CVE-2023-33005
Jenkins WSO2 Oauth Plugin 1.0 and previous versions does not invalidate the previous session on login.
Jenkins Wso2 Oauth
4.3
CVSSv3
CVE-2023-30527
Jenkins WSO2 Oauth Plugin 1.0 and previous versions stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Jenkins Wso2 Oauth
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »