Delinea records
13 published records for vendor delinea.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-26 Path Traversal: '/dir/../filename'2
- CWE-287 Improper Authentication2
- CWE-284 Improper Access Control1
- CWE-316 Cleartext Storage of Sensitive Information in Memory1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-321 Use of Hard-coded Cryptographic Key1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-33891No exploit | Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebServicedelinea · secret server · CWE-321 | High8.8 | — | 1.0% | Apr 28, 2024 |
33Monitor | CVE-2024-12908No exploit | Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the protocol handler function,delinea · secret server · CWE-94 | High8.3 | — | 0.7% | Dec 26, 2024 |
33Monitor | CVE-2024-25652No exploit | In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionadelinea · secret server · CWE-287 | High8.4 | — | 0.6% | Mar 13, 2024 |
28Monitor | CVE-2023-4589No exploit | Insufficient verification of data authenticity vulnerability in Delinea Secret Serverdelinea · secret server · CWE-345 | High7.2 | — | 0.3% | Sep 6, 2023 |
26Monitor | CVE-2024-5865No exploit | Arbitrary File Reading in Centrify PASdelinea · privileged access service · CWE-26 | Medium6.5 | — | 0.5% | Jul 2, 2024 |
26Monitor | CVE-2024-25649No exploit | In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the follodelinea · secret server · CWE-316 | Medium6.7 | — | 0.1% | Mar 13, 2024 |
23Monitor | CVE-2024-25650No exploit | Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmedelinea · distributed engine · CWE-319 | Medium5.9 | — | 0.3% | Mar 13, 2024 |
21Monitor | CVE-2024-25651No exploit | User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4.delinea · secret server · CWE-203 | Medium5.3 | — | 0.5% | Mar 13, 2024 |
21Monitor | CVE-2025-12810No exploit | Failure in Password Rotation and Check-in Mechanism in Secret Server Allows Reuse of Credentialsdelinea · secret server · CWE-287 | Medium5.3 | — | 0.5% | Jan 27, 2026 |
19Monitor | CVE-2023-4588No exploit | File accessibility vulnerability in Delinea Secret Serverdelinea · secret server · CWE-552 | Medium4.9 | — | 0.3% | Sep 6, 2023 |
17Monitor | CVE-2024-25653No exploit | Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is delinea · secret server · CWE-284 | Medium4.3 | — | 0.4% | Mar 13, 2024 |
17Monitor | CVE-2024-5866No exploit | Arbitrary Directory Listing in Centrify PASdelinea · privileged access service · CWE-26 | Medium4.3 | — | 0.4% | Jul 2, 2024 |
16Monitor | CVE-2025-6943No exploit | Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to rdelinea · secret server · CWE-269 | Medium4.0 | — | 0.2% | Jul 2, 2025 |
- CVE-2024-3389135Monitor
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService
HighCVSS 8.8No exploitEPSS 1%delinea · secret serverApr 28, 2024
- CVE-2024-1290833Monitor
Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the protocol handler function,
HighCVSS 8.3No exploitEPSS 1%delinea · secret serverDec 26, 2024
- CVE-2024-2565233Monitor
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functiona
HighCVSS 8.4No exploitEPSS 1%delinea · secret serverMar 13, 2024
- CVE-2023-458928Monitor
Insufficient verification of data authenticity vulnerability in Delinea Secret Server
HighCVSS 7.2No exploitEPSS 0%delinea · secret serverSep 6, 2023
- CVE-2024-586526Monitor
Arbitrary File Reading in Centrify PAS
MediumCVSS 6.5No exploitEPSS 0%delinea · privileged access serviceJul 2, 2024
- CVE-2024-2564926Monitor
In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the follo
MediumCVSS 6.7No exploitEPSS 0%delinea · secret serverMar 13, 2024
- CVE-2024-2565023Monitor
Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symme
MediumCVSS 5.9No exploitEPSS 0%delinea · distributed engineMar 13, 2024
- CVE-2024-2565121Monitor
User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4.
MediumCVSS 5.3No exploitEPSS 0%delinea · secret serverMar 13, 2024
- CVE-2025-1281021Monitor
Failure in Password Rotation and Check-in Mechanism in Secret Server Allows Reuse of Credentials
MediumCVSS 5.3No exploitEPSS 0%delinea · secret serverJan 27, 2026
- CVE-2023-458819Monitor
File accessibility vulnerability in Delinea Secret Server
MediumCVSS 4.9No exploitEPSS 0%delinea · secret serverSep 6, 2023
- CVE-2024-2565317Monitor
Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is
MediumCVSS 4.3No exploitEPSS 0%delinea · secret serverMar 13, 2024
- CVE-2024-586617Monitor
Arbitrary Directory Listing in Centrify PAS
MediumCVSS 4.3No exploitEPSS 0%delinea · privileged access serviceJul 2, 2024
- CVE-2025-694316Monitor
Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to r
MediumCVSS 4.0No exploitEPSS 0%delinea · secret serverJul 2, 2025