Show filters
46 Total Results
Displaying 11-20 of 46
Sort by:
Attacker Value
Unknown
CVE-2022-4943
Disclosure Date: October 20, 2023 (last updated October 27, 2023)
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings.
0
Attacker Value
Unknown
CVE-2023-1477
Disclosure Date: April 28, 2023 (last updated October 08, 2023)
Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, before 8.0.3.
0
Attacker Value
Unknown
CVE-2022-35850
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected cross site scripting (XSS) attack via the "reset-password" page.
0
Attacker Value
Unknown
CVE-2023-27895
Disclosure Date: March 14, 2023 (last updated October 08, 2023)
SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious app on the mobile device. The attacker could extract the currently views of the OTP and the secret OTP alphanumeric token during the token setup. On successful exploitation, an attacker can read some sensitive information but cannot modify and delete the data.
0
Attacker Value
Unknown
CVE-2023-26208
Disclosure Date: March 09, 2023 (last updated November 08, 2023)
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
0
Attacker Value
Unknown
CVE-2013-10013
Disclosure Date: January 17, 2023 (last updated October 08, 2023)
A vulnerability was found in Bricco Authenticator Plugin. It has been declared as critical. This vulnerability affects the function authenticate/compare of the file src/java/talentum/escenic/plugins/authenticator/authenticators/DBAuthenticator.java. The manipulation leads to sql injection. Upgrading to version 1.39 is able to address this issue. The name of the patch is a5456633ff75e8f13705974c7ed1ce77f3f142d5. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218428.
0
Attacker Value
Unknown
CVE-2022-3994
Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, which may deny other users access to the functionality in certain configurations.
0
Attacker Value
Unknown
CVE-2022-42461
Disclosure Date: October 31, 2022 (last updated December 22, 2024)
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
0
Attacker Value
Unknown
CVE-2022-35290
Disclosure Date: August 10, 2022 (last updated October 08, 2023)
Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2022-22304
Disclosure Date: July 18, 2022 (last updated October 07, 2023)
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
0