Products: 1
    Vulnerabilities: 11
    Known Exploited: 0
    3
    Critical Level Threats
    3
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-30059

    An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation of the chamado parameter through a crafted GET request.

    Last Modified: May 17, 2026
    Published: May 12, 2026

    CVE-2023-27753

    Arbitrary File Upload Enables Remote Code Execution in MK-Auth 23.01K4.9

    Last Modified: May 17, 2026
    Published: May 12, 2026

    CVE-2023-27246

    An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file.

    Last Modified: Feb 18, 2025
    Published: Mar 28, 2023

    CVE-2021-21495

    MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI.

    Last Modified: Nov 21, 2024
    Published: Jan 04, 2021

    CVE-2021-21494

    MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read the centralmka2 (session token) cookie, which is not set to HTTPOnly.

    Last Modified: Nov 21, 2024
    Published: Jan 04, 2021
    Items Per Page
    Mk-Auth Vulnerabilities & Security CVEs | CVE-DB