Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.46% | — | Moodle Catalyst User KEY Authentication PluginAI | 10/5/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affected by this vulnerability is an unknown functionality of the file /auth/userkey/logout.php of the component Logout. The manipulation of the argument return leads to open redirect. The attack can be… | |
| Aplazada | Baja (1.3) | 0.51% | — | Insa Rouen Insa-authAI | 7/5/2025 | 17/6/2026 | insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's secondary authentication bridge, potentially revealing basic student information (name and number). However, the issue posed minimal risk, was never exploited, and had limited impact. A fix was… | |
| Aplazada | Alta (7.5) | 0.77% | — | Publishpress AuthorsAI | 7/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress PublishPress Authors publishpress-authors allows PHP Local File Inclusion.This issue affects PublishPress Authors: from n/a through <= 4.7.5. | |
| Aplazada | Media (4.3) | 0.17% | — | Hossni Mubarak Cool Author BOXAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak Cool Author Box hm-cool-author-box-widget allows Cross Site Request Forgery.This issue affects Cool Author Box: from n/a through <= 3.0.0. | |
| Aplazada | Alta (8.6) | 0.37% | — | Auth0 Passport-wsfed-saml2AI | 6/5/2025 | 17/6/2026 | passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication by tampering with a valid SAML response. This can be done by adding attributes to… | |
| Aplazada | Crítica (9.3) | 0.42% | — | Auth0 Passport-wsfed-saml2AI | 6/5/2025 | 17/6/2026 | passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication by crafting a SAMLResponse. This can be done by using a valid SAML object that… | |
| Aplazada | Media (6.9) | 0.38% | — | Auth0 Account Link ExtensionAI | 1/5/2025 | 17/6/2026 | Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper authorization. This issue has been patched in… | |
| Analizada | Media (5.3) | 0.57% | — | Cloudflare Workers-oauth-provider | 1/5/2025 | 17/6/2026 | PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped. Fixed in: https://github.com/cloudflare/workers-oauth-provider/pull/27… | |
| Analizada | Media (6) | 0.32% | — | Cloudflare Workers-oauth-provider | 1/5/2025 | 17/6/2026 | The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on the allowed list of redirect URIs for the given client registration. Fixed in: https://github.com/cloudflare/workers-oauth-provider/pull/26… | |
| Aplazada | Media (4.9) | 0.43% | — | Auth0 Nextjs SDKAI | 29/4/2025 | 17/6/2026 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie… | |
| Analizada | Media (5.3) | 0.64% | — | Apereo Central Authentication Service | 27/4/2025 | 17/6/2026 | A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\core\cas-server-core-configuration-metadata-repository\src\main\java\org\apereo\cas\metadata\rest\CasConfigurationMetadataServerController.java. The manipulation of the… | |
| Analizada | Media (5.1) | 0.62% | — | Apereo Central Authentication Service | 27/4/2025 | 17/6/2026 | A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredServicesMultiActionController.java. The manipulation of the… | |
| Analizada | Baja (2.3) | 0.48% | — | Apereo Central Authentication Service | 27/4/2025 | 17/6/2026 | A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSimpleFormController.java of the component Groovy Code Handler.… | |
| Aplazada | Alta (7.1) | 0.29% | — | Claire Ryan Author ShowcaseAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Claire Ryan Author Showcase author-showcase allows Reflected XSS.This issue affects Author Showcase: from n/a through <= 1.4.3. | |
| Aplazada | Media (5.4) | 0.51% | — | Miniorange Wordpress Rest API AuthenticationAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress REST API Authentication wp-rest-api-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress REST API Authentication: from n/a through <= 3.6.3. | |
| Aplazada | Media (6.5) | 0.35% | — | Alan Petersen Author WIP Progress BARAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alan Petersen Author WIP Progress Bar author-work-in-progress-bar allows DOM-Based XSS.This issue affects Author WIP Progress Bar: from n/a through <= 1.0. | |
| Aplazada | Media (5.3) | 0.31% | — | Alembic ASH AuthenticationAI | 15/4/2025 | 17/6/2026 | Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered by clicking a link sent via email. Some email clients and security tools (e.g., Outlook, virus scanners, and email previewers) may automatically follow these links,… | |
| Aplazada | Media (5.4) | 0.27% | — | Wikimedia Mediawiki Oauth ExtensionAI | 11/4/2025 | 17/6/2026 | Incorrect Authorization vulnerability in The Wikimedia Foundation Mediawiki - OAuth Extension allows Authentication Bypass.This issue affects Mediawiki - OAuth Extension: from 1.39 through 1.43. | |
| Aplazada | Alta (8.2) | 0.58% | — | Apache MOD Auth OpenidcAI | 6/4/2025 | 17/6/2026 | mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.16.11, a bug in a mod_auth_openidc results in disclosure of protected content to unauthenticated users. The conditions for… | |
| Aplazada | Media (6.5) | 0.36% | — | Philip John Author BIO ShortcodeAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Philip John Author Bio Shortcode author-bio-shortcode allows Stored XSS.This issue affects Author Bio Shortcode: from n/a through <= 2.5.3. | |
| Aplazada | Alta (7.1) | 0.31% | — | Weblizar About AuthorAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weblizar - WordPress Themes & Plugin About Author about-author allows Reflected XSS.This issue affects About Author: from n/a through <= 1.6.2. | |
| Analizada | Alta (8.1) | 0.39% | — | Two-factor Authentication Project Two-factor Authentication | 31/3/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0. | |
| Analizada | Crítica (9.8) | 0.43% | — | Oauth2 Server Project Oauth2 Server | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0. | |
| Analizada | Media (6.8) | 0.18% | — | Mskcc Oauth2 Client | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal OAuth2 Client allows Cross Site Request Forgery.This issue affects OAuth2 Client: from 0.0.0 before 4.1.3. | |
| Analizada | Crítica (9.8) | 0.43% | — | Authenticator Login Project Authenticator Login | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authenticator Login: from 0.0.0 before 2.0.6. |