Vulnerabilities (CVE)

Filtered by CWE-565
Total 62 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-9820 1 Dueclic 1 Wp 2fa With Telegram 2024-10-19 N/A 6.5 MEDIUM
The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.
CVE-2024-9970 1 Newtype 1 Flowmaster Bpm Plus 2024-10-17 N/A 8.8 HIGH
The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.