Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.34% | — | Hivepress AuthenticationAI | 6/9/2026 | 8/9/2026 | The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to… | |
| Analizada | Media (5.4) | 0.30% | — | External Authentication Project External Authentication | 2/9/2026 | 15/9/2026 | Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13. | |
| Aplazada | Baja (2.1) | 0.75% | — | Alembic ASH AuthenticationAI | 25/8/2026 | 1/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction forms. When a strategy is configured with require_interaction? set to true, AshAuthentication serves an intermediate… | |
| Aplazada | Alta (7.6) | 0.58% | — | Alembic ASH AuthenticationAI | 25/8/2026 | 1/9/2026 | Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The bearer-token authentication helper AshAuthentication.Plug.Helpers.retrieve_from_bearer/3 verifies an… | |
| Aplazada | Crítica (9.1) | 0.70% | — | Cakephp AuthenticationAICakephpAI | 24/8/2026 | 9/9/2026 | CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy… | |
| Aplazada | Alta (8.1) | 0.47% | — | Firebase AuthenticationAI | 22/8/2026 | 26/8/2026 | The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators. | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | RSA Securid Authentication ManagerAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial parameter is not masked and is shown in… | |
| Aplazada | Media (5.9) | 0.47% | — | Steeltoe Security Authentication CloudfoundrybaseAISteeltoe Security Authentication JwtbearerAISteeltoe Security Authentication OpenidconnectAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authentication.OpenIdConnect… | |
| Aplazada | Crítica (9.2) | 0.68% | — | Alembic ASH AuthenticationAI | 15/6/2026 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in. AshAuthentication's OAuth2 and OIDC family strategies matched the local user by email address (an upsert on the email field, or a user-defined sign-in filter) rather than by… | |
| Aplazada | Crítica (9.1) | 0.37% | — | Catalyst Plugin AuthenticationAI | 9/6/2026 | 21/7/2026 | Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim. | |
| Aplazada | Media (4.3) | 0.21% | — | Two-factor AuthenticationAI | 27/5/2026 | 17/6/2026 | The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the ipv_save_changes function. This makes it possible for unauthenticated attackers to modify the… | |
| Aplazada | Media (5.1) | 0.18% | — | Perl Catalyst Plugin AuthenticationAI | 21/5/2026 | 23/7/2026 | Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. | |
| Aplazada | Media (6.5) | 0.38% | — | TWO Factor 2FA Authentication VIA EmailAI | 19/2/2026 | 17/6/2026 | The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 1.9.8. This is because the SS88_2FAVE::wp_login() method only enforces the 2FA requirement if the 'token' HTTP GET parameter is undefined, which makes it possible to… | |
| Aplazada | Alta (8.4) | 0.75% | — | Cyberoam Authentication ClientAI | 7/2/2026 | 17/6/2026 | Cyberoam Authentication Client 2.1.2.7 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) memory. Attackers can craft a malicious input in the 'Cyberoam Server Address' field to trigger a bind TCP shell on port 1337 with… | |
| Analizada | Media (4.2) | 0.18% | — | Jtenman Central Authentication System Server | 4/2/2026 | 17/6/2026 | XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2. | |
| Aplazada | Media (5.1) | 0.59% | — | Altitude Authentication ServiceAIAltitude Communication ServerAI | 26/1/2026 | 17/6/2026 | Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior… | |
| Aplazada | Media (6.5) | 0.31% | — | Miniorange 2 Factor AuthenticationAI | 18/12/2025 | 5/10/2026 | Missing Authorization vulnerability in miniOrange miniOrange's Google Authenticator miniorange-2-factor-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects miniOrange's Google Authenticator: from n/a through <= 6.1.1. | |
| Analizada | Crítica (9.8) | 0.54% | — | RSA Authentication Agent FOR Windows | 24/11/2025 | 17/6/2026 | In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead… | |
| Analizada | Alta (7.1) | 0.23% | — | Adobe Pass Authentication | 11/11/2025 | 17/6/2026 | Adobe Pass versions 3.7.3 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must install a malicious SDK. | |
| Aplazada | Baja (2.1) | 0.33% | — | Apereo Central Authentication ServiceAI | 27/10/2025 | 17/6/2026 | A vulnerability was detected in Zytec Dalian Zhuoyun Technology Central Authentication Service up to 20251009. This vulnerability affects the function _empty of the file /index.php/auth/widget. Performing manipulation of the argument get.layer/get.widget/get.action results in code injection. The attack is possible to… | |
| Aplazada | Alta (8.3) | 0.45% | — | Element Matrix-authentication-serviceAI | 16/10/2025 | 17/6/2026 | MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in matrix-authentication-service 0.20.0 through 1.4.0 allows an attacker with access to an authenticated MAS session to perform sensitive operations without… | |
| Aplazada | Alta (8.8) | 0.35% | — | Keyy TWO Factor AuthenticationAI | 15/10/2025 | 17/6/2026 | The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity associated with a token generated. This makes it possible for authenticated… | |
| Aplazada | Media (5.5) | 0.43% | — | Apereo Central Authentication ServiceAI | 5/10/2025 | 17/6/2026 | A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vulnerability is an unknown functionality of the file /index.php/auth/Ops/git of the component HTTP Header Handler. The manipulation of the argument Authorization leads to use of hard-coded password.… | |
| Aplazada | Alta (7.1) | 0.13% | — | Aaron Axelsen Wpmu Ldap AuthenticationAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Aaron Axelsen WPMU Ldap Authentication wpmuldap allows Stored XSS.This issue affects WPMU Ldap Authentication: from n/a through <= 5.0.1. | |
| Aplazada | Media (4.9) | 0.48% | — | Cisco DUO Authentication ProxyAI | 20/8/2025 | 17/6/2026 | A vulnerability in the debug logging function of Cisco Duo Authentication Proxy could allow an authenticated, high-privileged, remote attacker to view sensitive information in a system log file. |