Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1212 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.19%—Nick Powers Social Author BIOAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nick Powers Social Author Bio allows Stored XSS.This issue affects Social Author Bio: from n/a through 2.4.
AnalizadaMedia (4.3)0.58%—Authzed Spicedb10/4/202417/6/2026
SpiceDB is a graph database purpose-built for storing and evaluating access control data. Use of a relation of the form: `relation folder: folder | folder#parent` with an arrow such as `folder->view` can cause LookupSubjects to only return the subjects found under subjects for either `folder` or `folder#parent`. This…
ModificadaMedia (6.1)0.38%—Wp-oauth WP Oauth Server10/4/202417/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3.
AnalizadaAlta (8.1)0.66%—Workos Authkit-nextjs29/3/202417/6/2026
The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session by controlling the `x-workos-session` header. The vulnerability is patched in v0.4.2.
ModificadaMedia (6.1)0.40%—Fkrauthan Wp-mpdf21/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian 'fkrauthan' Krauthan allows Reflected XSS.This issue affects wp-mpdf: from n/a through 3.7.1.
AnalizadaCrítica (9.1)0.59%—Jupyter Oauthenticator20/3/202417/6/2026
OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's own Authenticators with any OAuth 2.0 provider. `GoogleOAuthenticator.hosted_domain` is used to restrict what Google accounts can be authorized access to a JupyterHub. The restriction is intented to…
AplazadaMedia (6.1)0.53%—Vmware Authorization ServerAI20/3/202417/6/2026
Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant. An application is not…
ModificadaAlta (7.1)1.3%—Microsoft Authenticator12/3/202417/6/2026
Microsoft Authenticator Elevation of Privilege Vulnerability
AnalizadaMedia (6.2)0.27%—Cisco DUO Authentication FOR Windows Logon AND RDP6/3/202417/6/2026
A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to invalidate locally created trusted sessions after a reboot of the affected device. An…
AnalizadaMedia (5.5)0.11%—Cisco DUO Authentication FOR Windows Logon AND RDP6/3/202417/6/2026
A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. This vulnerability is due to improper storage of an unencrypted registry key in certain logs. An attacker could…
AnalizadaCrítica (9.1)0.46%—Authzed Spicedb1/3/202417/6/2026
SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Integer overflow in chunking helper causes dispatching to miss elements or panic. Any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for…
AnalizadaAlta (7.8)0.34%💥 PoCThalesgroup Safenet Authentication Client27/2/202417/6/2026
A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access.
AnalizadaAlta (7.8)0.17%—Thalesgroup Safenet Authentication Client27/2/202417/6/2026
A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access.
AnalizadaAlta (8.1)0.80%—Discourse Microsoft Authentication21/2/202417/6/2026
`discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft-auth` plugin enabled, an attack can potentially take control of a victim's Discourse account. Sites that have configured their application's account type to any options other than `Accounts in this…
AplazadaAlta (7.8)0.35%—Vmware Enhanced Authentication Plug-inAI20/2/202417/6/2026
Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP session when initiated by a privileged domain user on the same system.
AplazadaCrítica (9.6)1.3%—Vmware Enhanced Authentication Plug-inAI20/2/202417/6/2026
Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory…
AnalizadaMedia (6.5)0.53%—Authcrunch Caddy-security17/2/202417/6/2026
All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several failed attempts to provide 2FA codes, attackers can bypass this blocking mechanism…
AnalizadaMedia (5.3)0.55%—Authcrunch Caddy-security17/2/202417/6/2026
All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within the network by exploiting this…
AnalizadaMedia (6.1)0.58%—Authcrunch Caddy-security17/2/202417/6/2026
All versions of the package github.com/greenpau/caddy-security are vulnerable to Cross-site Scripting (XSS) via the Referer header, due to improper input sanitization. Although the Referer header is sanitized by escaping some characters that can allow XSS (e.g., [&], [<], [>], ["], [']), it does not account for the…
AnalizadaAlta (8.1)0.71%—Authcrunch Caddy-security17/2/202417/6/2026
All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign Out" button. User sessions remain valid even after requests are sent to /logout and /oauth2/google/logout. Attackers who gain access to an…
ModificadaAlta (7.5)1.3%—MOD Auth OpenidcDebian LinuxFedoraproject Fedora13/2/202417/6/2026
mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes the server vulnerable to a denial of…
ModificadaMedia (6.1)0.37%—Authcrunch Caddy-security12/2/202417/6/2026
The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either a /admin or /settings/mfa/delete/ substring.
ModificadaMedia (5.4)0.51%—Shooflysolutions (simply) Guest Author Name5/2/202417/6/2026
The (Simply) Guest Author Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's post meta in all versions up to, and including, 4.34 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaAlta (7.5)0.65%—Amitzy Molongui Authorship5/2/202417/6/2026
The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.4 via the 'ma_debu' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including post author emails…
ModificadaAlta (8.8)0.54%—Goauthentik Authentik30/1/202417/6/2026
Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE offers. PKCE adds the code_challenge parameter to the authorization request and adds the code_verifier parameter to the token request. Prior to 2023.8.7 and…