Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8) | 0.39% | — | Goauthentik Authentik | 28/3/2025 | 17/6/2026 | authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-default setting), deleting sessions via the Web Interface or the API would not revoke the session and the session holder would continue to have… | |
| Aplazada | Media (6.9) | 0.40% | — | Centrify Authentication ServiceAI | 28/3/2025 | 17/6/2026 | User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker to determine whether an email address is registered through specific error messages. | |
| Aplazada | Media (4.3) | 0.21% | — | Nitin Prakash Product Author FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nitin Prakash Product Author for WooCommerce wc-product-author allows Cross Site Request Forgery.This issue affects Product Author for WooCommerce: from n/a through <= 1.0.7. | |
| Aplazada | Media (5.3) | 0.47% | — | Hossni Mubarak Cool Author BOXAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Hossni Mubarak Cool Author Box hm-cool-author-box-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cool Author Box: from n/a through <= 2.9.9. | |
| Aplazada | Alta (7.6) | 0.35% | — | Publishpress AuthorsAI | 15/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Authors publishpress-authors allows SQL Injection.This issue affects PublishPress Authors: from n/a through <= 4.7.3. | |
| Modificada | Alta (7.7) | 1.5% | — | Omniauth SamlOnelogin Ruby-saml | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to… | |
| Modificada | Crítica (9.3) | 65% | — | Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document… | |
| Modificada | Crítica (9.3) | 21% | — | Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document… | |
| Aplazada | Alta (7.1) | 0.39% | — | Rachel Cherry Authors Autocomplete Meta BOXAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry Authors Autocomplete Meta Box authors-autocomplete-meta-box allows Reflected XSS.This issue affects Authors Autocomplete Meta Box: from n/a through <= 1.2. | |
| Aplazada | Alta (7.1) | 0.38% | — | Montashov 4 Author Cheer UP DonateAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in montashov 4 author cheer up donate 4-author-cheer-up-donate allows Reflected XSS.This issue affects 4 author cheer up donate: from n/a through <= 1.3. | |
| Aplazada | Media (6.5) | 0.38% | — | THE Authors ListAI | 1/3/2025 | 17/6/2026 | The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers… | |
| Analizada | Crítica (9.8) | 0.36% | — | LTI Jupyterhub Authenticator | 25/2/2025 | 17/6/2026 | `jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only users that has… | |
| Analizada | Media (6.9) | 0.35% | — | Better-auth Better Auth | 24/2/2025 | 17/6/2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to version 1.1.21, the application is vulnerable to an open redirect due to improper validation of the callbackURL parameter in the email verification endpoint and any other endpoint that accepts callback url. While the server blocks… | |
| Aplazada | Media (6.5) | 0.22% | — | JON Bishop WP About AuthorAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jon Bishop WP About Author wp-about-author allows DOM-Based XSS.This issue affects WP About Author: from n/a through <= 1.5. | |
| Aplazada | Media (6) | 0.34% | — | Workos Hosted AuthkitAI | 24/2/2025 | 17/6/2026 | WorkOS Hosted AuthKit before 2025-01-07 allows a password authentication MFA bypass (by enrolling a new authentication factor) when the attacker knows the user's password. No exploitation occurred. | |
| Aplazada | Baja (2.3) | 0.38% | — | AutheliaAI | 19/2/2025 | 17/6/2026 | Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. If users are allowed to sign in via both username and email the regulation system treats these as separate login events. This leads to the regulation… | |
| Aplazada | Crítica (9.1) | 0.61% | — | Spid Aspnetcore AuthenticationAI | 18/2/2025 | 17/6/2026 | SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: Identity Provider (IDP): the system that authenticates users and provides identity information (SAML affirmation) to the Service Provider, in… | |
| Aplazada | Media (4.3) | 0.46% | — | RSA Authentication ManagerAI | 17/2/2025 | 17/6/2026 | RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur. | |
| Aplazada | Media (4) | 0.14% | — | Nitrokey 3 FirmwareAIPIV AuthenticatorAI | 12/2/2025 | 17/6/2026 | Nitrokey 3 Firmware is the the firmware of Nitrokey 3 USB keys. For release 1.8.0, and test releases with PIV enabled prior to 1.8.0, the PIV application could accept invalid keys for authentication of the admin key. This could lead to compromise of the integrity of the data stored in the application. An attacker… | |
| Analizada | Media (6.3) | 0.31% | — | Alembic ASH Authentication | 11/2/2025 | 17/6/2026 | Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have used the magic link strategy _or_ are manually revoking tokens are affected by revoked tokens being allowed to verify as… | |
| Aplazada | Alta (7.3) | 0.32% | — | Perfood Couch-authAI | 10/2/2025 | 17/6/2026 | A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information | |
| Analizada | Media (4.8) | 0.30% | — | Goauthentik Authentik | 4/2/2025 | 17/6/2026 | Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release. | |
| Aplazada | Alta (8.8) | 0.71% | — | GoauthAI | 28/1/2025 | 17/6/2026 | Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected credentials stored in the users .netrc file. | |
| Analizada | Media (6.8) | 0.31% | — | Jenkins Folder-based Authorization Strategy | 22/1/2025 | 17/6/2026 | Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to. | |
| Analizada | Alta (8.8) | 0.55% | — | Jenkins Openid Connect Authentication | 22/1/2025 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in… |