Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.21% | — | Fkrauthan Wp-mpdfAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fkrauthan wp-mpdf wp-mpdf allows Stored XSS.This issue affects wp-mpdf: from n/a through <= 3.9.1. | |
| Aplazada | Media (6.5) | 0.22% | — | Themeplugs AuthorsyAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeplugs Authorsy authorsy allows Stored XSS.This issue affects Authorsy: from n/a through <= 1.0.5. | |
| Aplazada | Media (4.3) | 0.17% | — | Miniorange Oauth Single Sign ONAI | 26/9/2025 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.26.12. This is due to using a predictable state parameter (base64 encoded app name) without any randomness in the OAuth flow. This makes it possible for unauthenticated… | |
| Modificada | Alta (7.5) | 0.26% | — | Authlib | 22/9/2025 | 17/6/2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 “must‑understand” semantics. An attacker can craft a signed token with a critical header (for example,… | |
| Aplazada | Media (5.9) | 0.22% | — | Russelljamieson AuthorsureAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson AuthorSure authorsure allows Stored XSS.This issue affects AuthorSure: from n/a through <= 2.3. | |
| Aplazada | Alta (7.5) | 0.41% | — | Apache Authany CookieAI | 17/9/2025 | 25/9/2026 | Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely. Session ids are generated using an MD5 hash of the epoch time and a call to the built-in rand function. The epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for… | |
| Aplazada | Media (4.3) | 0.14% | — | Wpkube Authors ListAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPKube Authors List authors-list allows Cross Site Request Forgery.This issue affects Authors List: from n/a through <= 2.0.6.2. | |
| Aplazada | Media (5.5) | 0.32% | — | John Luetke Media AuthorAI | 5/9/2025 | 5/10/2026 | Incorrect Privilege Assignment vulnerability in John Luetke Media Author media-author allows Privilege Escalation.This issue affects Media Author: from n/a through <= 1.0.4. | |
| Aplazada | Alta (7.1) | 0.13% | — | Aaron Axelsen Wpmu Ldap AuthenticationAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Aaron Axelsen WPMU Ldap Authentication wpmuldap allows Stored XSS.This issue affects WPMU Ldap Authentication: from n/a through <= 5.0.1. | |
| Aplazada | Media (4.9) | 0.48% | — | Cisco DUO Authentication ProxyAI | 20/8/2025 | 17/6/2026 | A vulnerability in the debug logging function of Cisco Duo Authentication Proxy could allow an authenticated, high-privileged, remote attacker to view sensitive information in a system log file. | |
| Analizada | Crítica (9.8) | 0.52% | — | Authenticator Login Project Authenticator Login | 15/8/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.4. | |
| Aplazada | Alta (7.1) | 0.26% | — | Federico Rota Authentication AND Xmlrpc LOG WriterAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Federico Rota Authentication and xmlrpc log writer authentication-and-xmlrpc-log-writer allows Reflected XSS.This issue affects Authentication and xmlrpc log writer: from n/a through <= 1.2.2. | |
| Aplazada | Alta (8.6) | 0.43% | — | Perl Catalyst Authentication Credential HttpAIPerl Data UuidAI | 11/8/2025 | 17/6/2026 | — | |
| Aplazada | Alta (7.1) | 0.37% | — | Workos-inc Authkit-remixAI | 9/8/2025 | 17/6/2026 | The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In versions 0.14.1 and below, @workos-inc/authkit-remix exposed sensitive authentication artifacts — specifically sealedSession and accessToken — by returning them from the… | |
| Aplazada | Alta (7.1) | 0.37% | — | Workos Authkit React RouterAI | 9/8/2025 | 17/6/2026 | The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKit with React Router. In versions 0.6.1 and below, @workos-inc/authkit-react-router exposed sensitive authentication artifacts — specifically sealedSession and accessToken by returning them from the… | |
| Aplazada | Media (6.1) | 0.31% | — | Opentext Advanced AuthenticationAI | 6/8/2025 | 17/6/2026 | A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the user authentication process to bypass Authentication. This issue affects Advanced Authentication on or before 6.5.0. | |
| Aplazada | Crítica (9.6) | 0.40% | — | Zscaler Saml AuthenticationAI | 5/8/2025 | 17/6/2026 | An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse. | |
| Analizada | Crítica (9.1) | 1.2% | — | Oauth2 Proxy Project Oauth2 Proxy | 30/7/2025 | 17/6/2026 | OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions 7.10.0 and below, oauth2-proxy deployments are vulnerable when using the skip_auth_routes configuration option with regex patterns.… | |
| Aplazada | Crítica (9.3) | 2.3% | 💥 Exploit | HybridauthAI | 25/7/2025 | 17/6/2026 | A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the install.php installation script. The script remains accessible after deployment and fails to sanitize input before writing to the application’s config.php file. An unauthenticated attacker can inject… | |
| Modificada | Media (6.5) | 0.30% | — | 2fauth | 24/7/2025 | 17/6/2026 | A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other operations are pending. | |
| Analizada | Alta (7.1) | 0.53% | — | Goauthentik Authentik | 23/7/2025 | 17/6/2026 | authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025.4.4 and earlier, as well as versions 2025.6.0-rc1 through 2025.6.3, deactivated users who registered through OAuth/SAML or linked their accounts to OAuth/SAML providers… | |
| Aplazada | Media (6.5) | 0.29% | — | Perl Authen Digestmd5AI | 16/7/2025 | 17/6/2026 | Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP… | |
| Aplazada | Media (6.5) | 0.44% | — | Authen Sasl Sasl Perl Digest MD5AI | 16/7/2025 | 17/6/2026 | Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked… | |
| Analizada | Media (6.5) | 0.40% | — | Two-factor Authentication Project Two-factor Authentication | 8/7/2025 | 17/6/2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0. | |
| Aplazada | Baja (2.1) | 0.36% | — | Better-auth Better AuthAI | 7/7/2025 | 17/6/2026 | Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /reset-password/:token, /delete-user/callback, /magic-link/verify, /oauth-proxy-callback. This vulnerability is fixed in… |