Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.21% | — | Perfood Couchauth | 20/11/2025 | 17/6/2026 | Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques, potentially… | |
| Analizada | Media (5.3) | 0.25% | — | Goauthentik Authentik | 19/11/2025 | 17/6/2026 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions, invitations were considered valid regardless if they are expired or not, thus relying on background tasks to clean up expired ones. In a normal scenario this can take up to 5 minutes because the… | |
| Analizada | Media (4.8) | 0.22% | — | Goauthentik Authentik | 19/11/2025 | 17/6/2026 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authentik versions, authentication for this account was possible even when the account… | |
| Analizada | Alta (7.1) | 0.23% | — | Adobe Pass Authentication | 11/11/2025 | 17/6/2026 | Adobe Pass versions 3.7.3 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must install a malicious SDK. | |
| Aplazada | Media (6.5) | 0.38% | — | Wpkube Authors ListAI | 11/11/2025 | 17/6/2026 | The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method call from Authors_List_Shortcode class. This makes it possible for authenticated attackers, with Contributor-level access and above, to call methods such as… | |
| Aplazada | Media (6.1) | 0.32% | — | Wp-oauthAI | 11/11/2025 | 7/10/2026 | The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Analizada | Baja (2.7) | 0.25% | — | Authzed Spicedb | 10/11/2025 | 17/6/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users who use the exclusion operator somewhere in their authorization schema; have configured their SpiceDB server such that `--write-relationships-max-updates-per-call` is bigger… | |
| Aplazada | Alta (8.5) | 0.62% | — | Oauth2 ProxyAI | 10/11/2025 | 17/6/2026 | OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions prior to 7.13.0, all deployments of OAuth2 Proxy in front of applications that normalize underscores to dashes in HTTP headers… | |
| Analizada | Alta (7.5) | 0.36% | — | Simple Oauth Project Simple Oauth | 30/10/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass.This issue affects Simple OAuth (OAuth2) & OpenID Connect: from 6.0.0 before 6.0.7. | |
| Aplazada | Alta (7.2) | 0.15% | — | Netknights Gmbh Privacyidea AuthenticatorAI | 27/10/2025 | 17/6/2026 | Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabling generation of… | |
| Aplazada | Baja (2.1) | 0.33% | — | Apereo Central Authentication ServiceAI | 27/10/2025 | 17/6/2026 | A vulnerability was detected in Zytec Dalian Zhuoyun Technology Central Authentication Service up to 20251009. This vulnerability affects the function _empty of the file /index.php/auth/widget. Performing manipulation of the argument get.layer/get.widget/get.action results in code injection. The attack is possible to… | |
| Aplazada | Alta (8.8) | 0.21% | 💥 PoC | IndieauthAI | 24/10/2025 | 17/6/2026 | The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4. This is due to missing nonce verification on the `login_form_indieauth()` function and the authorization endpoint at wp-login.php?action=indieauth. This makes it possible for unauthenticated… | |
| Modificada | Media (6.5) | 0.46% | — | Authlib | 22/10/2025 | 17/6/2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF path performs unbounded DEFLATE decompression. A very small ciphertext can expand into tens or hundreds of megabytes on decrypt, allowing an attacker who can supply decryptable tokens to exhaust… | |
| Aplazada | Media (6.9) | 0.44% | — | Wikimedia Mediawiki Centralauth ExtensionAI | 18/10/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects Mediawiki - CentralAuth Extension: from master before 1.39. | |
| Aplazada | Media (5.9) | 0.39% | — | Wikimedia Mediawiki Webauthn ExtensionAI | 17/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44. | |
| Aplazada | Alta (8.3) | 0.45% | — | Element Matrix-authentication-serviceAI | 16/10/2025 | 17/6/2026 | MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in matrix-authentication-service 0.20.0 through 1.4.0 allows an attacker with access to an authenticated MAS session to perform sensitive operations without… | |
| Aplazada | Alta (8.8) | 0.35% | — | Keyy TWO Factor AuthenticationAI | 15/10/2025 | 17/6/2026 | The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity associated with a token generated. This makes it possible for authenticated… | |
| Analizada | Alta (8.8) | 0.35% | — | Authenticator Login Project Authenticator Login | 10/10/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8. | |
| Modificada | Alta (7.5) | 0.64% | — | Authlib | 10/10/2025 | 17/6/2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose base64url‑encoded header or signature spans hundreds of megabytes. During verification,… | |
| Aplazada | Crítica (9.3) | 18% | — | Better-auth Better AuthAI | 9/10/2025 | 17/6/2026 | Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api-key/create` route. `session?.user ?? (authRequired ? null : { id:… | |
| Aplazada | Media (6.3) | 0.42% | — | Python Social AuthAI | 9/10/2025 | 17/6/2026 | Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate… | |
| Aplazada | Media (5.5) | 0.43% | — | Apereo Central Authentication ServiceAI | 5/10/2025 | 17/6/2026 | A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vulnerability is an unknown functionality of the file /index.php/auth/Ops/git of the component HTTP Header Handler. The manipulation of the argument Authorization leads to use of hard-coded password.… | |
| Aplazada | Crítica (9.8) | 0.60% | 💥 PoC | Oauth Single Sign ON SSOAI | 4/10/2025 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token processing without verification or validation in the `get_resource_owner_from_id_token`… | |
| Analizada | Media (6.9) | 0.22% | — | Qnap Authenticator | 3/10/2025 | 17/6/2026 | An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP Authenticator 1.3.1.1227 and later | |
| Aplazada | Baja (3.3) | 0.35% | — | Auth0-phpAI | 1/10/2025 | 17/6/2026 | auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import endpoint in applications built with the SDK does not validate the file-path wrapper or value. Without proper validation, affected applications may accept arbitrary file paths or URLs. The… |