Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1212 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.19%—A Jones Simply Guest Author NameAI4/7/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones (Simply) Guest Author Name guest-author-name allows DOM-Based XSS.This issue affects (Simply) Guest Author Name: from n/a through <= 4.36.
AplazadaAlta (8.8)0.45%—Wikimedia Mediawiki Centralauth ExtensionAI3/7/202517/6/2026
Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
AnalizadaMedia (5.5)0.52%—Goauthentik Authentik27/6/202517/6/2026
authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and is sent to the client in the URL. This token is intended to only be valid for the session of the user who authorized the connection, however this check is…
AplazadaMedia (5.3)0.28%—Zealousweb Accept Authorize.net Payments Using Contact Form 7AI27/6/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Authorize.NET Payments Using Contact Form 7 accept-authorize-net-payments-using-contact-form-7 allows Retrieve Embedded Sensitive Data.This issue affects Accept Authorize.NET Payments Using Contact Form 7: from n/a through <= 2.5.
AplazadaBaja (2.3)0.50%—Ash-project ASH Authentication PhoenixAI17/6/202522/9/2026
Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards. The default sign_out/2 that AshAuthentication.Phoenix.Controller injects into an application's auth controller only calls Plug.Conn.clear_session/1. It…
AnalizadaAlta (8.5)0.30%—Canonical Authd16/6/202517/6/2026
A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.
AplazadaMedia (5.7)0.33%—AuthorinoAI9/6/202517/6/2026
A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster
AplazadaMedia (5.7)0.30%—Redhat AuthorinoAI9/6/202517/6/2026
The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona to add callbacks to be executed to HTTP endpoints once the authorization process is completed. It was found that an attacker with developer persona access…
AnalizadaMedia (5.3)0.32%—Authzed Spicedb6/6/202517/6/2026
SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a CheckPermission request involves the evaluation of multiple caveated branches, requests may return a…
AplazadaAlta (7.1)0.15%—David Shabtai Post AuthorAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in David Shabtai Post Author post-author allows Stored XSS.This issue affects Post Author: from n/a through <= 1.1.1.
AplazadaAlta (7.7)0.43%—Nextjs-auth0AI4/6/202517/6/2026
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK versions 4.0.1 through 4.6.0, `__session` cookies set by auth0.middleware may be cached by CDNs due to missing Cache-Control headers. Three preconditions must be met in order for someone to be affected…
AplazadaCrítica (9.3)0.75%—Auth0-phpAI3/6/202517/6/2026
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafted cookie containing…
AplazadaBaja (2.7)0.86%—Supabase Auth-jsAI27/5/202517/6/2026
auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.70.0, the library functions getUserById, deleteUser, updateUserById, listFactors and deleteFactor did not require the user supplied values to be valid UUIDs. This could lead to a URL path traversal, resulting in the wrong API function…
AplazadaBaja (2.1)0.18%—Opentext Advanced AuthenticationAI27/5/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentication allows Information Elicitation. The vulnerability could reveal sensitive information while managing and configuring of the external services. This issue affects Advanced Authentication versions…
AplazadaAlta (7.1)0.27%—Sftranna Ec-authorizenetAI23/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sftranna EC Authorize.net ec-authorizenet allows Reflected XSS.This issue affects EC Authorize.net: from n/a through <= 0.3.3.
AplazadaMedia (6.5)0.20%—Lloyd Saunders Author BOX After PostsAI19/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lloyd Saunders Author Box After Posts author-box-after-posts allows Stored XSS.This issue affects Author Box After Posts: from n/a through <= 1.6.
AplazadaMedia (4.3)0.14%—Sanjeev Mohindra Author BOX With Different DescriptionAI19/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Sanjeev Mohindra Author Box Plugin With Different Description author-box-with-different-description allows Cross Site Request Forgery.This issue affects Author Box Plugin With Different Description: from n/a through <= 1.3.5.
AplazadaCrítica (9.1)0.54%—Auth0 PHPAI15/5/202517/6/2026
Auth0-PHP provides the PHP SDK for Auth0 Authentication and Management APIs. Starting in version 8.0.0-BETA1 and prior to version 8.14.0, session cookies of applications using the Auth0-PHP SDK configured with CookieStore have authentication tags that can be brute forced, which may result in unauthorized access.…
AnalizadaMedia (4.3)0.17%—Jfarthing Custom Author Base15/5/202517/6/2026
The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AnalizadaMedia (5.4)0.31%—Freebiesdownload PVN Auth Popup15/5/202517/6/2026
The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
AnalizadaMedia (4.8)0.32%—Freebiesdownload PVN Auth Popup15/5/202517/6/2026
The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaMedia (5.4)0.29%—Pgina ForkAIPgina HttpauthAI15/5/202517/6/2026
The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary controls DNS resolution for pginaloginserver.
AnalizadaCrítica (9.8)0.64%—Jenkins Wso2 Oauth14/5/202517/6/2026
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.
AplazadaCrítica (9.4)0.41%—Opentext Advanced AuthenticationAI14/5/202517/6/2026
Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5.
AplazadaAlta (7.5)0.29%—Opentext Advanced AuthenticationAI14/5/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5
Orbitaley — Vulnerabilidades