Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
53 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.42% | — | Nextcloud User Oidc | 15/11/2024 | 17/6/2026 | user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a provided URL after successfully authenticating. It is recommended that the Nextcloud User OIDC app is upgraded to 6.1.0. | |
| Aplazada | Media (5.3) | 0.48% | — | Voidcoders Void Elementor Post Grid AddonAI | 19/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elementor Page builder allows PHP Local File Inclusion.This issue affects Void Elementor Post Grid Addon for Elementor Page builder: from n/a through 2.3. | |
| Analizada | Media (4.8) | 0.26% | — | Voidcoders Void Contact Form 7 Widget FOR Elementor Page Builder | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder allows Stored XSS.This issue affects Void Contact Form 7 Widget For Elementor Page Builder: from n/a through 2.4.1. | |
| Modificada | Media (5.4) | 0.34% | — | Voidcoders Void Contact Form 7 Widget FOR Elementor Page Builder | 2/7/2024 | 17/6/2026 | The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cf7_redirect_page' attribute within the plugin's Void Contact From 7 widget in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping on user… | |
| Analizada | Media (4.7) | 0.24% | — | Nextcloud User Oidc | 14/6/2024 | 17/6/2026 | user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.5, 2.0.0, 3.0.0, 4.0.0 or 5.0.0. | |
| Analizada | Media (6.3) | 0.64% | — | Nextcloud User Oidc | 14/6/2024 | 17/6/2026 | user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is available to all registered users. It is recommended that the OpenID Connect user backend is upgraded to 3.0.0 (Nextcloud… | |
| Analizada | Media (5.5) | 0.15% | — | IBM Security Verify Access Oidc Provider | 31/5/2024 | 17/6/2026 | IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. IBM X-Force ID: 279978. | |
| Aplazada | Media (6.5) | 0.32% | — | Voidcoders Void Elementor Whmcs Elements FOR Elementor Page BuilderAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VoidCoders, innovs Void Elementor WHMCS Elements For Elementor Page Builder allows Stored XSS.This issue affects Void Elementor WHMCS Elements For Elementor Page Builder: from n/a through 2.0. | |
| Analizada | Media (6.1) | 0.41% | — | Boidcms | 17/4/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Content parameter. | |
| Analizada | Media (6.1) | 0.43% | — | Boidcms | 17/4/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Permalink parameter. | |
| Aplazada | Media (5.3) | 0.24% | — | OidccAI | 4/4/2024 | 17/6/2026 | oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling `oidcc_provider_configuration_worker:get_provider_configuration/1` or `oidcc_provider_configuration_worker:get_jwks/1`. This issue has been patched in version(s)`3.1.2` & `3.2.0-beta.3`. | |
| Modificada | Alta (8.8) | 0.41% | — | Voidcoders Void Contact Form 7 Widget FOR Elementor Page Builder | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder.This issue affects Void Contact Form 7 Widget For Elementor Page Builder: from n/a through 2.3. | |
| Modificada | Media (6.1) | 0.50% | — | Kantega-sso Kantega Saml SSO Oidc Kerberos Single Sign-on | 29/12/2023 | 17/6/2026 | The Kantega SAML SSO OIDC Kerberos Single Sign-on apps before 6.20.0 for Atlassian products allow XSS if SAML POST Binding is enabled. This affects 4.4.2 through 4.14.8 before 4.14.9, 5.0.0 through 5.11.4 before 5.11.5, and 6.0.0 through 6.19.0 before 6.20.0. The full product names are Kantega SAML SSO OIDC Kerberos… | |
| Modificada | Media (5.4) | 0.46% | — | Boidcms | 7/12/2023 | 17/6/2026 | BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or keywords parameter in a page=create action. | |
| Modificada | Media (5.3) | 0.52% | — | IBM Security Verify Access Oidc Provider | 14/10/2023 | 17/6/2026 | IBM Security Verify Access OIDC Provider could disclose directory information that could aid attackers in further attacks against the system. IBM X-Force ID: 239445. | |
| Modificada | Alta (7.5) | 1.00% | — | IBM Security Verify Access Oidc Provider | 14/10/2023 | 17/6/2026 | IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 238921. | |
| Modificada | Alta (8.8) | 76% | 💥 Exploit | Boidcms | 21/8/2023 | 9/7/2026 | File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks. | |
| Modificada | Alta (8.1) | 0.44% | — | Nextcloud User Oidc | 10/8/2023 | 17/6/2026 | user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at least read access to a snapshot of the database can impersonate the Nextcloud server towards linked servers. user_oidc 1.3.3 contains a… | |
| Modificada | Media (4.8) | 0.54% | — | Nextcloud User Oidc | 10/8/2023 | 17/6/2026 | user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, missing verification of the issuer would have allowed an attacker to perform a man-in-the-middle attack returning corrupted or known token they also have access to.… | |
| Modificada | Crítica (9.8) | 0.85% | — | Nextcloud User Oidc | 25/5/2023 | 17/6/2026 | user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2 | |
| Modificada | Media (5.4) | 0.33% | — | Nextcloud User Oidc | 4/4/2023 | 17/6/2026 | user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in versions 1.0.0 until 1.3.0 effectively allowed an attacker to bypass the state protection as they could just copy the expected state token from the first request to their second request. Users should… | |
| Modificada | Alta (8.8) | 0.27% | — | Voidcoders Void Contact Form 7 Widget FOR Elementor Page Builder | 13/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions. | |
| Modificada | Media (4.7) | 0.41% | — | Okta Oidc Middleware | 12/1/2023 | 17/6/2026 | An open redirect vulnerability exists in Okta OIDC Middleware prior to version 5.0.0 allowing an attacker to redirect a user to an arbitrary URL. | |
| Modificada | Alta (8.2) | 6.1% | 💥 Exploit | Shibboleth Oidc OP | 4/2/2022 | 17/6/2026 | The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services. | |
| Modificada | Alta (7.4) | 0.82% | — | Flask-oidc Project Flask-oidc | 7/10/2016 | 17/6/2026 | flask-oidc version 0.1.2 and earlier is vulnerable to an open redirect |