One-identity
5 CVEs tracked since 2025. Since Jul 2025, none of them reached CISA KEV.
One-identity CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-07 | 5 | 0 |
Products
The products that kept showing up in One-identity's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 8 most recently published vulnerabilities affecting One-identity.
- CVE-2025-59363In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),7.7
- CVE-2025-52924In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.4.0
- CVE-2025-27582The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within the kiosk browser ...7.6
- CVE-2025-34064OneLogin AD Connector Log S3 Bucket Hijack Leading to Cross-Tenant Data Leakage9.3
- CVE-2025-34063OneLogin AD Connector JWT Authentication Bypass via Exposed Signing Key10.0
- CVE-2025-34062OneLogin AD Connector API Credential and Signing Key Exposure—
- CVE-2024-47619tranport: TLS host name wildcard matching too lax7.5
- CVE-2022-38725An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or n...7.5
The record
- Peak rank
- #192 in Jul 2025
- Busiest month shown
- Jul 2025, 5 CVEs
- Months with a KEV entry
- 0 since Jul 2025
- Monthly snapshots
- 1 since 2025