Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
oauth vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-33005
Jenkins WSO2 Oauth Plugin 1.0 and previous versions does not invalidate the previous session on login.
Jenkins Wso2 Oauth
NA
CVE-2022-3631
The OAuth Client by DigitialPixies WordPress plugin up to and including 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall...
Digitialpixies Oauth Client
NA
CVE-2022-3632
The OAuth Client by DigitialPixies WordPress plugin up to and including 1.1.0 does not have CSRF checks in some places, which could allow malicious users to make logged-in users perform unwanted actions.
Digitialpixies Oauth Client
4.3
CVSSv2
CVE-2019-1003018
An exposure of sensitive information vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and previous versions in GithubSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. mali...
Jenkins Github Oauth
NA
CVE-2023-45144
com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and ...
Xwiki Oauth Identity
7.5
CVSSv2
CVE-2015-9435
The oauth2-provider plugin prior to 3.1.5 for WordPress has incorrect generation of random numbers.
Dash10 Oauth Server
NA
CVE-2023-33006
A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and previous versions allows malicious users to trick users into logging in to the attacker's account.
Jenkins Wso2 Oauth
NA
CVE-2023-24427
Jenkins Bitbucket OAuth Plugin 0.12 and previous versions does not invalidate the previous session on login.
Jenkins Bitbucket Oauth
NA
CVE-2022-4148
The WP OAuth Server (OAuth Authentication) WordPress plugin prior to 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
Dash10 Oauth Server
NA
CVE-2022-3894
The WP OAuth Server (OAuth Authentication) WordPress plugin prior to 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow malicious users to make a logged in admin delete arbitrary client ...
Dash10 Oauth Server
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49333
CVE-2024-33901
CVE-2024-36001
CVE-2024-2835
firewall
XPath injection
authentication bypass
CVE-2024-22120
CVE-2024-32002
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »