Veridiumid develops biometric and identity authentication solutions, with its vulnerability exposure centered on the VeridiumAD product line and reflecting application-layer input-handling and authentication control challenges. The recurring weakness classes—cross-site scripting, improper authentication, and HTTP request smuggling—are typical of web-facing identity and access management systems where request parsing and credential validation are critical. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Veridiumid over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42791HIGH An issue was discovered in VeridiumID VeridiumAD 2.5.3.0. The HTTP request to trigger push notifications for VeridiumAD enrolled users does not enforce proper access control. A use | Jan 28, 2022 | 7.3 | 23 | NO | NO |
CVE-2023-44039CRITICAL In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enroll a FIDO key) to register the | Apr 3, 2024 | 9.1 | 22 | NO | NO |
CVE-2023-45552MEDIUM In VeridiumID before 3.5.0, a stored cross-site scripting (XSS) vulnerability has been discovered in the admin portal that allows an authenticated attacker to take over all account | Apr 3, 2024 | 6.5 | 21 | NO | NO |
CVE-2023-44038MEDIUM In VeridiumID before 3.5.0, the identity provider page allows an unauthenticated attacker to discover information about registered users via an LDAP injection attack. | Apr 3, 2024 | 6.5 | 19 | NO | NO |
CVE-2023-44040MEDIUM In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker fo | Apr 3, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Veridiumid.
Media articles that mention a CVE ID that affects a product developed by Veridiumid — matched by CVE ID, not by vendor name.