Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
login vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-2987
The Ldap WP Login / Active Directory Integration WordPress plugin prior to 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated malicious users to update them. Attackers could set th...
Ldap Wp Login \\/ Active Directory Integration Project Ldap Wp Login \\/ Active Directory Integration
NA
CVE-2023-41936
Jenkins Google Login Plugin 1.7 and previous versions uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing malicious users to use statistical methods to obtain a valid token.
Jenkins Google Login
4.3
CVSSv2
CVE-2017-18501
The social-login-bws plugin prior to 0.2 for WordPress has multiple XSS issues.
Bestwebsoft Social Login
4.3
CVSSv2
CVE-2018-1000173
A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized malicious users to impersonate another user if they can control the pre-authentication session.
Jenkins Google Login
5.8
CVSSv2
CVE-2018-1000174
An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows malicious users to redirect users to an arbitrary URL after successful login.
Jenkins Google Login
NA
CVE-2023-37946
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and previous versions does not invalidate the previous session on login.
Jenkins Openshift Login
NA
CVE-2023-37947
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and previous versions improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing malicious users to perform phishing attacks.
Jenkins Openshift Login
10
CVSSv2
CVE-2007-1766
PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the root parameter.
Msxstudios Advanced Login
1 EDB exploit
7.5
CVSSv2
CVE-2007-4342
PHP remote file inclusion vulnerability in include.php in PHPCentral Login 1.0 allows remote malicious users to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter. NOTE: a third party disputes this vulnerability because of the special nature of the SERVE...
Phpcentral Login 1.0
NA
CVE-2023-22958
The Syracom Secure Login plugin prior to 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidation target parameter.
Syracom Secure Login
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »