Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.63% | — | Jenkins Openid Connect Authentication | 2/10/2024 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins. | |
| Analizada | Alta (8.7) | 0.52% | — | Expressjs Basic-auth-connect | 30/9/2024 | 17/6/2026 | basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0. | |
| Modificada | Media (5.4) | 0.41% | — | Axton Wp-webauthn | 28/9/2024 | 17/6/2026 | The WP-WebAuthn plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wwa_login_form shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.42% | — | Goauthentik Authentik | 27/9/2024 | 17/6/2026 | authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a user can steal an access token they were legitimately issued for one application… | |
| Analizada | Crítica (9) | 0.57% | — | Goauthentik Authentik | 27/9/2024 | 17/6/2026 | authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an unparsable IP address, e.g. `a`. This results in a possibility of logging into any account with a known login or email address.… | |
| Aplazada | Media (5.3) | 0.36% | — | Tmsoft Myauth GatewayAI | 27/9/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of the file /index.php. The manipulation of the argument console/nocache/cmd leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.3) | 0.58% | — | Watchguard Authentication Gateway | 25/9/2024 | 8/8/2026 | Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and… | |
| Modificada | Crítica (9.3) | 1.2% | 💥 PoC | Watchguard Authentication GatewayWatchguard Single Sign-on Client | 25/9/2024 | 8/8/2026 | An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an… | |
| Analizada | Media (5.3) | 0.29% | — | Authzed Spicedb | 18/9/2024 | 17/6/2026 | spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect subject type on the same relation can result in no permission being returned when permission is expected. If the resource has multiple groups,… | |
| Modificada | Alta (7.5) | 0.50% | — | Mfasoft Secure Authentication Server | 16/9/2024 | 17/6/2026 | An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain access to user tokens without authentication. The is a brute-force attack on the serial parameter by… | |
| Modificada | Alta (7.5) | 0.56% | — | Opendaylight Authentication, Authorization AND Accounting | 15/9/2024 | 17/6/2026 | An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information. | |
| Modificada | Crítica (9.8) | 11% | 💥 PoC | Onelogin Ruby-samlOmniauth SamlGitlab | 10/9/2024 | 17/6/2026 | The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with… | |
| Analizada | Media (5.5) | 0.11% | — | Cisco DUO Authentication FOR Epic | 4/9/2024 | 17/6/2026 | A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This vulnerability is due to improper storage of an unencrypted registry key. A low-privileged attacker could exploit this vulnerability by viewing or querying… | |
| Modificada | Alta (7.8) | 0.09% | — | Authenticator | 3/9/2024 | 17/6/2026 | Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to brute-force the user's encryption key.… | |
| Analizada | Media (5.3) | 0.24% | — | Youtag Two-factor Authentication | 31/8/2024 | 17/6/2026 | The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with… | |
| Analizada | Alta (8.2) | 0.29% | — | Microfocus Netiq Advanced Authentication | 28/8/2024 | 17/6/2026 | A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before 6.3.5.1 | |
| Analizada | Alta (8.8) | 0.18% | — | Microfocus Netiq Advanced Authentication | 28/8/2024 | 17/6/2026 | Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices. This issue affects NetIQ Advance Authentication versions before 6.3.5.1 | |
| Analizada | Alta (7.2) | 0.53% | — | Microfocus Netiq Advanced Authentication | 28/8/2024 | 17/6/2026 | A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1. | |
| Analizada | Crítica (9.9) | 0.23% | — | Microfocus Netiq Advanced Authentication | 28/8/2024 | 17/6/2026 | A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This issue impacts all NetIQ Advance Authentication before 6.3.5.1 | |
| Analizada | Media (5.5) | 0.16% | — | Microfocus Netiq Advanced Authentication | 28/8/2024 | 17/6/2026 | A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication version before 6.3.5.1 | |
| Analizada | Media (6.5) | 0.21% | — | Microfocus Netiq Advanced Authentication | 28/8/2024 | 17/6/2026 | A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1 | |
| Analizada | Alta (7.5) | 0.48% | — | Goauthentik Authentik | 22/8/2024 | 17/6/2026 | authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs/<uuid>/view_certificate/, /api/v3/crypto/certificatekeypairs/<uuid>/view_private_key/, and… | |
| Aplazada | Media (6.5) | 0.24% | — | Atlassian OauthAI | 15/8/2024 | 17/6/2026 | In the OAuth library for nim prior to version 0.11, the Authorization Code grant and Implicit grant both rely on the `state` parameter to prevent cross-site request forgery (CSRF) attacks where a resource owner might have their session associated with protected resources belonging to an attacker. When this project is… | |
| Aplazada | Media (6.5) | 0.25% | — | Atlassian OauthAI | 15/8/2024 | 17/6/2026 | In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not have sufficient entropy. These can be successfully guessed by an attacker allowing them to perform a CSRF vs a user, associating the user's session with the attacker's protected resources. While… | |
| Analizada | Alta (7.2) | 0.44% | — | Abinitio Authorization GatewayAbinitio Metadata HUB | 8/8/2024 | 17/6/2026 | An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted modification of server configuration. |