All CVEs — page 86 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows an attacker to bypass PKCE validation for public Relying Parties, enabling them to obtain user tokens by replaying client_id with an arbitrary secret.
The flaw allows unauthenticated OAuth2 token introspection, enabling attackers to confirm token validity and extract metadata, potentially translating user identifiers across Relying Parties.
The flaw allows execution of Python code from an obfuscated URL, enabling arbitrary code execution as the user.
This flaw allows an attacker to disable a path or route a later request past an authorization check by leveraging a dispatch memo keyed on the request path alone, potentially leading to unauthorized access or denial of service.
The iSteamX mobile application's AWS policy flaw allows authenticated users to access wildcard MQTT topics, exposing other users' device data and potentially scalding due to unintended device activation.