Products: 4
    Vulnerabilities: 8
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-27370

    OpenID Connect Core through 1.0 errata set 2 allows audience injection in certain situations. When the private_key_jwt authentication mechanism is used, a malicious Authorization Server could trick a Client into writing attacker-controlled values into the audience, including token endpoints or issuer identifiers of other Authorization Servers. The malicious Authorization Server could then use these private key JWTs to impersonate the Client.

    Last Modified: Apr 15, 2026
    Published: Mar 03, 2025

    CVE-2008-3280

    It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number Generator (CVE-2008-0166). In combination with the DNS Cache Poisoning issue (CVE-2008-1447) and the fact that almost all SSL/TLS implementations do not consult CRLs (currently an untracked issue), this means that it is impossible to rely on these OPs.

    Last Modified: Nov 21, 2024
    Published: May 21, 2021

    CVE-2019-11027

    rubygem-ruby-openid: Unknown remotely exploitable flaw

    Last Modified: Nov 21, 2024
    Published: Jun 10, 2019

    CVE-2019-9837

    Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redirect_uri field in an OAuth authorization request (that results in an error response) with the 'openid' scope and a prompt=none value. This allows phishing attacks against the authorization flow.

    Last Modified: Nov 21, 2024
    Published: Mar 15, 2019

    CVE-2011-4314

    extension): MITM due to improper validation of AX attribute signatures

    Last Modified: Apr 11, 2025
    Published: May 05, 2011
    Items Per Page