Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ruby Saml CRITICAL 9.1
CVE-2025-66567

The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentic…

Fix: 1.18.0+
Fix from $2,300 2025-12-09
Ruby Saml CRITICAL 9.1
CVE-2025-66568

The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypa…

Fix: 1.18.0+
Fix from $2,300 2025-12-09
Ruby Saml CRITICAL 9.8
CVE-2015-20108

xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.

Fix: 1.0.0+
Fix from $2,300 2023-05-27
Onelogin Saml Sso HIGH 7.5
CVE-2016-10928

The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.

Fix: 2.2.0+
Fix from $1,950 2019-08-22
Pythonsaml CRITICAL 9.8
CVE-2017-11427

OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attack…

Fix: after 2.3.0
Fix from $2,300 2019-04-17
Ruby Saml CRITICAL 9.8
CVE-2017-11428

OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacke…

Fix: after 1.6.0
Fix from $2,300 2019-04-17
Ruby Saml HIGH 7.5
CVE-2016-5697

Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.

Fix: after 1.2.0
Fix from $1,950 2017-01-23