Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.4
CVE-2025-67505
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from con…
Java Management Sdk
20.0.1+
MEDIUM 5.3
CVE-2025-66033
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementat…
Java Management Sdk
24.0.1+
HIGH 7.8
CVE-2024-9191
The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers …
Verify
5.3.3+
HIGH 7.8
CVE-2024-7061
Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.…
Verify
5.0.2+
MEDIUM 6.7
CVE-2023-0392
The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.
Ldap Agent
5.18+
MEDIUM 5.4
CVE-2021-45094
Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS.
Imprivata Privileged Access Management
No fix yet
HIGH 8.8
CVE-2023-0093
Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An o…
Advanced Server Access
1.68.2+
HIGH 8.8
CVE-2022-1030
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafte…
Advanced Server Access
1.58.0+
HIGH 8.8
CVE-2022-24295EPSS 17%
Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL.
Advanced Server Access Client For Windows
1.57.0+
MEDIUM 6.7
CVE-2021-28113EPSS 22%
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin …
Access Gateway
after 2020.8.4