Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2024-41952
Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mit…
Zitadel
2.53.9 / 2.54.8+
MEDIUM 6.5
CVE-2024-39683
ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (brows…
Zitadel
2.53.8 / 2.54.5+
MEDIUM 5.3
CVE-2024-32967
Zitadel is an open source identity management system. In case ZITADEL could not connect to the database, connection information including db name, us…
Zitadel
2.45.7 / 2.46.7+
HIGH 8.1
CVE-2024-32868
ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL al…
Zitadel
2.50.0+
HIGH 8.7
CVE-2024-29891
ZITADEL users can upload their own avatar image and various image types are allowed. Due to a missing check, an attacker could upload HTML and preten…
Zitadel
2.42.17 / 2.43.11+
MEDIUM 6.1
CVE-2024-28855
ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use of the `text/template` inste…
Zitadel
2.41.15 / 2.42.15+
HIGH 7.5
CVE-2024-28197
Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the…
Zitadel
2.44.3+
HIGH 8.8
CVE-2023-49097
ZITADEL is an identity infrastructure system. ZITADEL uses the notification triggering requests Forwarded or X-Forwarded-Host header to build the but…
Zitadel
2.39.9 / 2.40.10+
MEDIUM 5.4
CVE-2023-46238
ZITADEL is an identity infrastructure management system. ZITADEL users can upload their own avatar image using various image types including SVG. SVG…
Zitadel
2.38.2 / 2.39.2+
MEDIUM 5.3
CVE-2023-44399
ZITADEL provides identity infrastructure. In versions 2.37.2 and prior, ZITADEL administrators can enable a setting called "Ignoring unknown username…
Zitadel
after 2.37.2
MEDIUM 5.9
CVE-2023-22492
ZITADEL is a combination of Auth0 and Keycloak. RefreshTokens is an OAuth 2.0 feature that allows applications to retrieve new access tokens and refr…
Zitadel
2.16.4 / 2.17.3+
HIGH 8.8
CVE-2022-36051
ZITADEL combines the ease of Auth0 and the versatility of Keycloak.**Actions**, introduced in ZITADEL **1.42.0** on the API and **1.56.0** for Consol…
Zitadel
1.87.1 / 2.2.0+