Filter
-Infinity
0

IBM Cognos Analyticsjsonwebtoken unrestricted key type could lead to legacy keys usage

8.1
First published (updated )

IBM Cognos Analyticsjsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC

First published (updated )

IBM Cognos Analyticsjsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()

7.6
First published (updated )

Auth0 Passport WSFED SAML2Passport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authentication

7.5
First published (updated )

Auth0HTML injection with additional signup fields

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Auth0 Express Openid ConnectOpen Redirect in express-openid-connect

7.5
First published (updated )

Auth0Open redirect in nextjs-auth0

First published (updated )

Auth0 Express Openid ConnectSession fixation in express-openid-connect

8.8
First published (updated )

Auth0Reflected XSS from the callback handler's error query parameter

First published (updated )

Auth0Reflected XSS when using flashMessages

8.1
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Auth0 AD/LDAP ConnectorCSRF in Auth0 ad-ldap-connector

8.8
First published (updated )

rubygems/omniauth-auth0Regression in JWT Signature Validation

First published (updated )

Auth0DOM-based XSS in auth0-lock

First published (updated )

Auth0Authorization header is not sanitized in an error object in auth0

7.7
First published (updated )

Auth0 Express JWTAuthorization bypass in express-jwt

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Auth0Information disclosure through error object

First published (updated )

Auth0 LoginAn issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform …

8.8
First published (updated )

Auth0 LoginInput Validation

First published (updated )

Auth0CSRF

8.8
First published (updated )

Auth0 LoginXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Auth0XSS

First published (updated )

Auth0 LoginXSS

First published (updated )

npm/auth0-lockXSS

First published (updated )

nuget/Auth0.AuthenticationApiAuth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be acci…

7.5
First published (updated )

Auth0 PassportAuth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before…

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Auth0Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when i…

First published (updated )

Auth0CSRF

8.8
First published (updated )

npm/angular-jwtInput Validation

First published (updated )

jsonwebtokenInput Validation

First published (updated )

Auth0The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audie…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203