Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1211 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.28% | — | Backstage Plugin-auth-backend-module-oidc-providerAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. Prior to 0.4.20, the @backstage/plugin-auth-backend-module-oidc-provider package is affected by improper authentication in the oidc provider. Deployments using OIDC email-based identity resolution with a provider that permits unverified email addresses may… | |
| Pendiente de análisis | Media (6.8) | 0.31% | — | Backstage Plugin-auth-nodeAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. From 0.3.0 until 0.6.15 and 0.7.5, the @backstage/plugin-auth-node package did not consistently honor explicit negative email verification during shared OAuth profile normalization. The affected paths include a selected profile email marked verified:… | |
| Pendiente de análisis | Media (6.8) | 0.28% | — | Backstage Plugin-auth-backend-module-cloudflare-access-providerAI | 6/10/2026 | 7/10/2026 | Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access auth provider. The Cloudflare Access auth provider verifies a token's signature… | |
| Aplazada | Crítica (9.8) | 0.64% | — | Json API AuthAIPI Media Json APIAI | 2/10/2026 | 3/10/2026 | The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query… | |
| Pendiente de análisis | Crítica (9.8) | 0.17% | — | AuthlibAI | 1/10/2026 | 5/10/2026 | Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server… | |
| Aplazada | Crítica (9.8) | 0.27% | 💥 PoC | AuthorizerAI | 1/10/2026 | 1/10/2026 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions. | |
| Pendiente de análisis | Media (6.1) | 0.24% | — | Oauth-proxyAI | 1/10/2026 | 6/10/2026 | A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external… | |
| Pendiente de análisis | Alta (7.2) | 0.28% | 💥 PoC | Wikimedia CentralauthAI | 30/9/2026 | 30/9/2026 | External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection. This issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43. | |
| Aplazada | Media (6.5) | 0.13% | — | Dash10 Oauth ServerAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. | |
| Aplazada | Crítica (9.8) | 0.30% | — | Oauth Single Sign ON SSOAI | 30/9/2026 | 30/9/2026 | Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Wikimedia CentralauthAI | 29/9/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS. This issue affects Mediawiki - CentralAuth extension: before 1.46.1, 1.45.5, 1.43.10. | |
| Pendiente de análisis | Alta (7.5) | 0.26% | — | Wikimedia CentralauthAI | 29/9/2026 | 30/9/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows Excavation. This issue affects Mediawiki - CentralAuth Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Pendiente de análisis | Crítica (9.8) | 0.28% | 💥 PoC | AuthlibAI | 28/9/2026 | 1/10/2026 | Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key. | |
| En análisis | Media (6.3) | 0.35% | — | RabbitmqAIRabbitmq Auth Backend LdapAI | 25/9/2026 | 28/9/2026 | RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2, and 4.3 maintenance lines but contains conflicting first-fixed versions for the 3.13, 4.0, and 4.1 lines. fill/2 substitutes ${username} into user_dn_pattern without RFC 4514 DN escaping, allowing a crafted username to… | |
| Aplazada | Crítica (9.8) | 0.27% | — | Friendsofflarum OauthAI | 25/9/2026 | 30/9/2026 | FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing the address to Flarum core as trusted through provideTrustedEmail(). When… | |
| Aplazada | Baja (3.7) | 0.23% | — | Django-allauthAI | 25/9/2026 | 30/9/2026 | django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit. | |
| Aplazada | Media (5.4) | 0.21% | — | TinyauthAI | 25/9/2026 | 30/9/2026 | tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression. | |
| Pendiente de análisis | Media (4.2) | 0.16% | — | Python Social AuthAI | 24/9/2026 | 30/9/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to… | |
| Pendiente de análisis | Alta (7.4) | 0.16% | — | Python Social AuthAI | 24/9/2026 | 28/9/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a… | |
| Pendiente de análisis | Media (4.3) | 0.11% | — | Python Social AuthAI | 24/9/2026 | 5/10/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication… | |
| Pendiente de análisis | Media (6.8) | 0.22% | — | Python Social AuthAI | 24/9/2026 | 29/9/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could… | |
| Pendiente de análisis | Media (6.4) | 0.23% | — | Python Social AuthAI | 24/9/2026 | 5/10/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker… | |
| Aplazada | Alta (7.5) | 0.64% | — | Goauthentik AuthentikAI | 24/9/2026 | 29/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The message can stop the worker handling /application/saml/* or… | |
| Aplazada | Alta (7.4) | 0.27% | — | Goauthentik AuthentikAI | 24/9/2026 | 24/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider issued the assertion for that Source or in response to a login request from that Source. The SAML… | |
| Aplazada | Alta (8.1) | 0.33% | — | Goauthentik AuthentikAI | 24/9/2026 | 24/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected… |