Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.19% | — | Crowdstrike Oauth API APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password parameter is not masked and is shown in… | |
| Aplazada | Alta (7.5) | 0.51% | — | NET OauthAI | 19/8/2026 | 26/8/2026 | Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally computed one with the eq operator, which returns as soon as the two strings differ. The time… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Atlassian OauthAI | 19/8/2026 | 26/8/2026 | Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to check a signature is chosen by whoever… | |
| Aplazada | Alta (8.8) | 0.62% | — | Goauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings that can contain stored credentials. The… | |
| Aplazada | Crítica (9.4) | 0.59% | — | Goauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity provider's signed assertion. An attacker with an account on the source… | |
| Aplazada | Media (5.3) | 0.44% | — | Goauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization filter used by the rest of the API. Any party able to reach the API, including an unauthenticated client, can invoke the diagnostic action… | |
| Aplazada | Alta (8.6) | 0.68% | — | Google ChromeAIGoogle Verified Access APIAIGoauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED… | |
| Aplazada | Media (6.5) | 0.55% | — | Atlassian OauthAI | 16/8/2026 | 26/8/2026 | Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash with no bound and no eviction, and keeps an entry for every class name it is asked about, including names that failed to load, because… | |
| Aplazada | Crítica (9.8) | 0.72% | — | Digitialpixies Oauth ClientAI | 16/8/2026 | 26/8/2026 | Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the constructor selects OAuth 1.0a. get_request_token then revokes that choice when the request token response omits oauth_callback_confirmed, with no… | |
| Analizada | Media (5.4) | 0.10% | — | Fastify/oauth2 | 15/8/2026 | 4/9/2026 | @fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefixed, predictable cookie, with no server-side binding to the browser that began the… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Digitialpixies Oauth ClientAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. | |
| Pendiente de análisis | Media (4.3) | 0.36% | — | Oauth-serverAI | 11/8/2026 | 14/8/2026 | A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled… | |
| Aplazada | Alta (8.8) | 0.40% | — | Goauthentik AuthentikAI | 11/8/2026 | 3/9/2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts… | |
| Aplazada | Alta (8.8) | 0.42% | — | Goauthentik AuthentikAI | 11/8/2026 | 3/9/2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SCIM group that matches an existing administrator group by name. The SCIM group ingest function adopts any existing group… | |
| Aplazada | Crítica (9.3) | 0.40% | — | WP Oauth ServerAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | |
| Pendiente de análisis | Media (6.5) | 0.18% | — | Openshift Oauth-proxyAI | 5/8/2026 | 6/8/2026 | A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject… | |
| Aplazada | Media (5.3) | 0.26% | — | Better-auth Oauth-providerAI | 1/8/2026 | 8/9/2026 | @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain access tokens whose audience targets resource servers the authorization never covered, bypassing… | |
| Pendiente de análisis | Alta (7.2) | 0.19% | — | Atlassian OauthAI | 28/7/2026 | 9/9/2026 | OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer's configuration and… | |
| Pendiente de análisis | Alta (8.6) | 0.45% | — | Oauth2AI | 28/7/2026 | 5/10/2026 | OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host,… | |
| Pendiente de análisis | Alta (8.5) | 0.53% | — | Openshift Oauth-proxyAI | 28/7/2026 | 21/9/2026 | A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated… | |
| Aplazada | Media (5.3) | 0.37% | — | Django-oauth-toolkitAI | 19/7/2026 | 20/7/2026 | A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators.py. The manipulation leads to session expiration. The attack can be initiated remotely. The project was informed of the problem early… | |
| Analizada | Alta (7.6) | 0.41% | — | Better-auth/oauth-providerBetter-auth Better Auth | 15/7/2026 | 21/7/2026 | Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a single-use authorization code through a non-atomic find-then-delete sequence, allowing two concurrent requests to… | |
| Analizada | Alta (8.1) | 0.42% | — | Better-auth/oauth-providerBetter-auth Better Auth | 15/7/2026 | 21/7/2026 | Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint sequence on the oauthRefreshToken row, allowing concurrent requests… | |
| Aplazada | Media (4.4) | 0.41% | — | Lockme Oauth2 Calendars IntegrationAI | 11/7/2026 | 13/7/2026 | The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output escaping. The register_setting() call on line 197 lacks a sanitize callback,… | |
| Aplazada | Crítica (9.8) | 0.73% | — | Miniorange Oauth Single Sign ON - SSOAI | 10/7/2026 | 21/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8. |