Balázs Orbán
6 exploits
Active since Jun 2022
next-auth < 3.29.5 - Denial of Service via Malformed Callback URL
CVSS 7.5
next-auth < 3.29.5 - Denial of Service via Malformed Callback URL
CVSS 7.5
next-auth < 3.29.8 and < 4.9.0 - Cross-Site Scripting via Email Sign-In Endpoint
CVSS 7.1
NextAuth.js <4.10.3, 3.29.10 - Info Disclosure
CVSS 9.1
next-auth < 3.0.2 - Improper Authentication via Upstash Redis Adapter Email Callback
CVSS 6.8
next-auth < 4.24.5 - Improper Authorization via Middleware JWT Manipulation
CVSS 5.3