Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.43% | — | Oauth2 Proxy Project Oauth2 Proxy | 22/4/2026 | 17/6/2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of patterns that can be… | |
| Modificada | Crítica (9.1) | 0.73% | — | Oauth2 Proxy Project Oauth2 Proxy | 22/4/2026 | 15/7/2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route` is configured. An attacker can spoof this header so OAuth2 Proxy… | |
| Analizada | Media (6.8) | 0.34% | — | Oauth2 Proxy Project Oauth2 Proxy | 21/4/2026 | 17/6/2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain enforcement option. An attacker may be able to authenticate with an email claim such as attacker@evil.com@company.com and satisfy an allowed… | |
| Analizada | Media (5.4) | 0.26% | — | Nextjs-auth0 | 17/4/2026 | 17/6/2026 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the proxy cache fetcher to perform improper lookups for the token request results. Users are affected if their project uses both… | |
| Analizada | Media (4.4) | 0.18% | — | Authzed Spicedb | 15/4/2026 | 17/6/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions 1.49.0 through 1.51.0, when SpiceDB starts with log level info, the startup "configuration" log will include the full datastore DSN, including the plaintext password, inside DatastoreConfig.URI.… | |
| Analizada | Media (5.5) | 0.11% | — | Linuxfoundation Sigstore Timestamp Authority | 15/4/2026 | 17/6/2026 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimestampResponse correctly verifies the certificate chain signature, but the TSA-specific constraint checks in VerifyLeafCert… | |
| Analizada | Crítica (9.1) | 0.66% | — | Oauth2 Proxy Project Oauth2 Proxy | 14/4/2026 | 24/7/2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an auth_request-style integration (such as nginx auth_request) and either --ping-user-agent is set or… | |
| Analizada | Baja (3.5) | 0.22% | — | Oauth2 Proxy Project Oauth2 Proxy | 14/4/2026 | 24/7/2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when rendering the sign-in page. In deployments that rely on the sign-in page as part of their logout flow, a user may be shown the sign-in page… | |
| Aplazada | Media (5.3) | 0.31% | — | Paul Bearne Author Avatars List BlockAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Author Avatars List/Block: from n/a through <= 2.1.25. | |
| Pendiente de análisis | Alta (8.8) | 0.45% | — | Wikimedia Mediawiki Centralauth ExtensionAI | 7/4/2026 | 21/7/2026 | Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure. The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45. | |
| Analizada | Baja (2.3) | 0.37% | — | Nhost/auth | 6/4/2026 | 17/6/2026 | Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback flow places the refresh token directly into the redirect URL as a query parameter. Refresh tokens in URLs are logged in browser history, server access logs, HTTP Referer headers, and proxy/CDN logs.… | |
| Analizada | Media (5.9) | 0.41% | — | LTI Jupyterhub Authenticator | 3/4/2026 | 24/7/2026 | LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-level dictionary that grows without bounds. Nonces are added before signature validation, so an attacker with knowledge of a valid consumer key can send repeated requests… | |
| Analizada | Alta (8.8) | 0.64% | — | Jupyter Oauthenticator | 3/4/2026 | 24/7/2026 | OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is used as the… | |
| Analizada | Alta (7.7) | 0.33% | — | Tinyauth | 2/4/2026 | 17/6/2026 | Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations (GenericOAuthService, GithubOAuthService, GoogleOAuthService) store PKCE verifiers and access tokens as mutable struct fields on singleton instances shared across all concurrent requests. When two… | |
| Modificada | Alta (8.2) | 0.48% | — | Miguelgrinberg Flask-httpauth | 1/4/2026 | 17/6/2026 | Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a request to a token protected resource without passing a token, or passing an empty token, Flask-HTTPAuth would invoke the application's token verification callback… | |
| Analizada | Crítica (9.8) | 0.32% | — | Auth0-php | 1/4/2026 | 17/6/2026 | Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat actors brute-forcing the encryption key and forging session cookies. This issue has… | |
| Modificada | Crítica (9.3) | 0.47% | — | Gematik Authenticator | 27/3/2026 | 17/6/2026 | Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gematik Authenticator to… | |
| Modificada | Alta (7.8) | 0.30% | — | Gematik Authenticator | 27/3/2026 | 17/6/2026 | Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnerable to remote code execution, triggered when victims open a malicious file. Update the gematik Authenticator to version… | |
| Analizada | Media (4.2) | 0.21% | — | Bojanz Openid Connect / Oauth Client | 26/3/2026 | 17/6/2026 | Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client allows Privilege Escalation.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0. | |
| Analizada | Media (6.5) | 0.42% | — | Bojanz Openid Connect / Oauth Client | 26/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authentication Bypass.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0. | |
| Analizada | Media (4.3) | 0.27% | — | Bojanz Openid Connect / Oauth Client | 26/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forgery.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0. | |
| Analizada | Baja (0.5) | 0.32% | — | Authelia | 26/3/2026 | 17/6/2026 | Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In version 4.39.15, an attacker may potentially be able to inject javascript into the Authelia login page if several conditions are met simultaneously.… | |
| Aplazada | Alta (7.5) | 0.29% | — | Publishpress AuthorsAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through <= 4.10.1. | |
| Aplazada | Media (6.3) | 0.26% | — | HybridauthAI | 23/3/2026 | 17/6/2026 | A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpClient/Curl.php of the component SSL Handler. The manipulation of the argument curlOptions results in improper certificate validation. The attack can be launched remotely. This attack is characterized… | |
| Aplazada | Media (6.1) | 0.27% | — | Axton Wp-webauthnAI | 21/3/2026 | 17/6/2026 | The WP-WebAuthn plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the `wwa_auth` AJAX endpoint in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on user supplied attributes logged by the plugin. This makes it possible for… |