Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.9) | 1.1% | — | Goauthentik Authentik | 21/11/2024 | 17/6/2026 | authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured in a provider, authentik will automatically use the first redirect_uri value received as an allowed redirect URI, without escaping characters that have… | |
| Analizada | Media (6.4) | 0.58% | — | Goauthentik Authentik | 21/11/2024 | 17/6/2026 | authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue. | |
| Analizada | Alta (7.5) | 0.59% | — | 2fauth | 20/11/2024 | 17/6/2026 | 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Two interconnected vulnerabilities exist in version 5.4.1 a SSRF and URI validation bypass issue. The endpoint at POST /api/v1/twofaccounts/preview allows setting a remote URI to retrieve the image of a 2fa site.… | |
| Analizada | Media (6.1) | 0.37% | — | 2fauth | 20/11/2024 | 17/6/2026 | 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Versions prior to 5.4.1 are vulnerable to stored cross-site scripting due to improper headers in direct access to uploaded SVGs. The application allows uploading images in several places. One of the accepted types… | |
| Aplazada | Alta (7.1) | 0.21% | — | Microkid Custom Author URLAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in microkid Custom Author URL author-slug allows Stored XSS.This issue affects Custom Author URL: from n/a through <= 2.0.1. | |
| Aplazada | Media (4.9) | 0.37% | — | Oauth-serverAI | 15/11/2024 | 26/6/2026 | A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug higher for OIDC/GitHub/GitLab/Google IDPs login options. | |
| Analizada | Media (5.3) | 0.62% | — | Apereo Central Authentication Service | 14/11/2024 | 17/6/2026 | A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (6.3) | 0.75% | — | Apereo Central Authentication Service | 14/11/2024 | 17/6/2026 | A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be… | |
| Analizada | Media (5.3) | 0.36% | — | Apereo Central Authentication Service | 14/11/2024 | 17/6/2026 | A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Alta (8.8) | 0.64% | — | Jenkins Openid Connect Authentication | 13/11/2024 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login. | |
| Analizada | Alta (8) | 0.69% | — | Jenkins Authorize Project | 13/11/2024 | 17/6/2026 | Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Aplazada | Media (4.8) | 0.32% | — | Secusuite Secure Client Authentication SCA ServerAI | 12/11/2024 | 17/6/2026 | An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number. | |
| Aplazada | Baja (2.1) | 0.22% | — | AuthkitAIRemixAI | 5/11/2024 | 17/6/2026 | The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.4.1. All users are advised… | |
| Analizada | Baja (2.1) | 0.25% | — | Workos Authkit-nextjs | 5/11/2024 | 17/6/2026 | The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.13.2 and all users are… | |
| Modificada | Alta (8.8) | 0.44% | — | Brandonwhite Author Discussion | 20/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brandon White Author Discussion author-discussion allows Blind SQL Injection.This issue affects Author Discussion: from n/a through <= 0.2.2. | |
| Modificada | Media (6.1) | 0.29% | — | Arifnezami Better Author BIO | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arifnezami Better Author Bio better-author-bio allows Reflected XSS.This issue affects Better Author Bio: from n/a through <= 2.7.10.11. | |
| Aplazada | Alta (8.8) | 0.51% | — | Publishpress AuthorsAI | 17/10/2024 | 17/6/2026 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct Object Reference to Privilege Escalation/Account Takeover in all versions up to, and including, 4.7.1 via the action_edited_author() due to missing validation on the… | |
| Analizada | Baja (2.4) | 0.32% | — | Authzed Spicedb | 14/10/2024 | 17/6/2026 | SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled `LookupResources2` and have caveats in the evaluation path for their requests can return a permissionship of `CONDITIONAL` with context… | |
| Aplazada | Alta (7.2) | 0.51% | — | Afthemes WP Post AuthorAI | 12/10/2024 | 17/6/2026 | The WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the linked_user_id parameter in all versions up to, and including, 3.8.1 due… | |
| Analizada | Media (6.4) | 0.28% | — | Canonical Authd | 10/10/2024 | 17/6/2026 | Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain their privileges. | |
| Aplazada | Media (6.5) | 0.26% | — | Axton Wp-webauthnAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Axton WP-WebAuthn wp-webauthn allows Stored XSS.This issue affects WP-WebAuthn: from n/a through <= 1.3.1. | |
| Aplazada | Media (6.5) | 0.26% | — | Paul Bearne Author Avatars List BlockAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.21. | |
| Analizada | Media (6.9) | 0.51% | — | Lifplatforms LIF Authentication Server | 4/10/2024 | 17/6/2026 | Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct code. If the attacker knew the email of… | |
| Analizada | Alta (8.8) | 0.58% | — | Canonical Authd | 3/10/2024 | 17/6/2026 | Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them. | |
| Analizada | Alta (8.1) | 0.63% | — | Jenkins Openid Connect Authentication | 2/10/2024 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins. |