Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
1208 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9) | 0.19% | — | WP Oauth ServerAI | 23/9/2026 | 24/9/2026 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and… | |
| Aplazada | Media (6.9) | 0.48% | — | TinyauthAI | 21/9/2026 | 30/9/2026 | Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_controller.go loginHandler and internal/middleware/context_middleware.go basicAuth… | |
| Aplazada | Media (5.3) | 0.60% | — | TinyauthAI | 21/9/2026 | 24/9/2026 | Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a global login lockdown. internal/controller/user_controller.go loginHandler passes each… | |
| Aplazada | Alta (8.1) | 0.61% | — | TinyauthAI | 21/9/2026 | 24/9/2026 | Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to bypass per-app access controls with a differently cased hostname. The… | |
| Aplazada | Alta (7.4) | 0.74% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in. AshAuthentication.Plug.Helpers.store_in_session/2 writes the authenticated subject into the existing session with… | |
| Aplazada | Crítica (9.1) | 0.77% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own account. AshAuthentication.Plug.Helpers.sign_in_using_remember_me/3 skips… | |
| Aplazada | Crítica (9.1) | 0.66% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established through a different connection. The strategy is meant to keep each connection in its own identity… | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | Steeltoe.security.authorization.certificateAI | 17/9/2026 | 30/9/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the… | |
| Aplazada | Crítica (9.1) | 0.75% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs. AshAuthentication.Strategy.OAuth2.UserResolver.resolve/3 matches an existing account using the register action's upsert_identity… | |
| Aplazada | Crítica (9.1) | 0.91% | — | Team-alembic ASH Authentication PhoenixAIAlembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled stores its session value as <jti>:<subject>.… | |
| Aplazada | Media (6.3) | 0.74% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters. AshAuthentication.Strategy.Password.RequestPasswordReset.run/3 interpolates the… | |
| Aplazada | Crítica (9.1) | 0.77% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.check_user/2 decides whether the attribute named by require_confirmed_with is set… | |
| Aplazada | Crítica (9.1) | 0.56% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A magic link configured with single_use_token?, which is the default, is meant to be redeemable exactly… | |
| Aplazada | Alta (8.2) | 0.74% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key. AshAuthentication.Base.decode62/1 in lib/ash_authentication/base.ex splits its argument into one binary per character… | |
| Aplazada | Baja (1.8) | 0.14% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant to pseudonymise. AshAuthentication.AddOn.AuditLog.IpPrivacy.hash_ip/1 computes a single unkeyed… | |
| Aplazada | Baja (1.8) | 0.18% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthentication.AddOn.AuditLog.Auditor.build_extra_data/4, which takes :actor from the… | |
| Aplazada | Alta (7.6) | 0.66% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A confirmation token issued to one user is accepted on any other user's record.… | |
| Aplazada | Baja (2.3) | 0.61% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account. AshAuthentication.Strategy.OAuth2.Plug.callback/2 clears the stored session_params through a… | |
| Aplazada | Alta (7.2) | 0.21% | — | Team-alembic ASH Authentication PhoenixAIAlembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its owner. After a successful password sign-in,… | |
| Aplazada | Alta (7.6) | 0.64% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Strategy.Password.SignInWithTokenPreparation.extract_primary_keys_from_subject/2 parses the JWT sub… | |
| Aplazada | Media (6.9) | 0.44% | — | Alembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthentication.TokenResource.RevokeTokenChange.change/3 reads the :token argument and decodes it… | |
| Aplazada | Media (5.3) | 0.16% | — | Wpmanageninja FluentauthAI | 17/9/2026 | 19/9/2026 | Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2. | |
| Aplazada | Alta (8.8) | 0.52% | — | Next-tinacms-azureAISupabase AuthAI | 16/9/2026 | 30/9/2026 | Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any… | |
| Pendiente de análisis | Alta (8.1) | 0.47% | — | Fastify AuthAI | 16/9/2026 | 17/9/2026 | @fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are composed with the relation "or" option together with the run "all" option and one entry is a nested array acting as an AND group, the… | |
| Pendiente de análisis | Media (4.3) | 0.33% | — | Jenkins Keycloak Authentication PluginAI | 16/9/2026 | 18/9/2026 | Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. |