Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. KnowBe4/
  3. KnowBe4 SecurityCoach

KnowBe4 SecurityCoach

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 33/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 4 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Real-time security coaching tool that provides feedback at point of risky action

by KnowBe4 · knowbe4.com · source ↗

Known CVEs (4)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2020-36845 ↗MEDIUM 5.32025

    The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a SCRIPT element that…

  • CVE-2020-36844 ↗MEDIUM 6.12025

    The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS. The response has a SCRIPT element that sets window.location.href to a JavaScript URL.

  • CVE-2024-29210 ↗LOW 2.82024

    A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifically within its configuration management functionalities. This vulnerability allow…

  • CVE-2024-29209 ↗MEDIUM 6.02024

    A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which could allow an attacker to remotely execute arbitrary code on the host machine.…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other GRC & Compliance Automation products

see all →
  • 3rdRisk Platform · 3rdRisk Solutions B.V.
  • 3rdcomply · 3rdcomply
  • 6clicks GRC · 6clicks
  • A-LIGN A-SCEND · A-LIGN
  • ANOZR WAY AY PeopleSight · ANOZR WAY
  • ARCON Security Compliance Management · ARCON
  • ASPIA Audit Management · ASPIA Infotech Pvt. Ltd.
  • ASPIA KRI Module · ASPIA Infotech Pvt. Ltd.