Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.45% | — | Nextcloud SSO & Saml Authentication | 18/1/2024 | 17/6/2026 | Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or 6.0.1. There are no known workarounds for… | |
| Modificada | Alta (7.5) | 0.38% | — | Lifplatforms LIF Auth Server | 12/1/2024 | 17/6/2026 | Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` and `get_banner` routes on Auth Server. The issue is that there is no check to ensure that the file that Auth Server is receiving through these URLs is correct. This could… | |
| Modificada | Media (5.4) | 0.55% | — | Goauthentik Authentik | 11/1/2024 | 17/6/2026 | Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with `response_mode=form_post`. This relatively user could use the described attacks to perform a privilege escalation. This vulnerability has been… | |
| Modificada | Crítica (9.6) | 0.52% | — | Perfood Couchauth | 3/1/2024 | 17/6/2026 | A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password… | |
| Modificada | Crítica (9.8) | 0.90% | — | Recognizeapp Omniauth\ | 2/1/2024 | 17/6/2026 | omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute of the user nor did it give/document an option to do so, making it susceptible to nOAuth misconfiguration in cases when the `email` is… | |
| Modificada | Alta (7.5) | 0.70% | — | Miniorange Google Authenticator | 29/12/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA , Two Factor, OTP SMS and Email | Passwordless login.This issue affects miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA ,… | |
| Modificada | Media (6.5) | 1.2% | — | Michaelkelly Duouniversalkeycloakauthenticator | 23/12/2023 | 17/6/2026 | An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. A user logging into Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this… | |
| Modificada | Alta (8.8) | 0.49% | — | Yiiframework Yii2-authclient | 22/12/2023 | 17/6/2026 | yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE implementation is vulnerable in 2 ways. First, the `authCodeVerifier` should be removed after usage (similar to `authState`). Second, there… | |
| Modificada | Crítica (9.8) | 0.72% | — | Yiiframework Yii2-authclient | 22/12/2023 | 17/6/2026 | yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth1/2 `state` and OpenID Connect `nonce` is vulnerable for a `timing attack` since it is compared via regular string comparison (instead of… | |
| Modificada | Media (5.4) | 0.37% | — | Webfactoryltd Guest Author | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebFactory Ltd Guest Author allows Stored XSS.This issue affects Guest Author: from n/a through 2.3. | |
| Modificada | Media (6.1) | 0.40% | — | Marzocca List ALL Posts BY Authors Nested Categories AND Titles | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fabio Marzocca List all posts by Authors, nested Categories and Titles allows Reflected XSS.This issue affects List all posts by Authors, nested Categories and Titles: from n/a through 2.7.10. | |
| Modificada | Alta (8.2) | 0.46% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Carbon Identity Application Authentication Endpoint+1 | 15/12/2023 | 17/6/2026 | Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: Attacker should have: When all preconditions are met, a malicious actor could use JIT provisioning… | |
| Modificada | Media (4.7) | 0.43% | — | Beckhoff Authelia-bhf | 14/12/2023 | 17/6/2026 | The package authelia-bhf included in Beckhoffs TwinCAT/BSD is prone to an open redirect that allows a remote unprivileged attacker to redirect a user to another site. This may have limited impact to integrity and does solely affect anthelia-bhf the Beckhoff fork of authelia. | |
| Modificada | Media (5.4) | 0.39% | — | Bearne Author Avatars List/block | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through 2.1.17. | |
| Analizada | Media (6.1) | 0.60% | — | Jenkins Openid Connect Authentication | 13/12/2023 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks. | |
| Modificada | Media (6.1) | 0.56% | — | Owncloud Oauth2 | 21/11/2023 | 17/6/2026 | An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently allows an attacker to redirect callbacks to a Top Level Domain controlled by the attacker. | |
| Modificada | Crítica (9.8) | 1.2% | — | Goauthentik Authentik | 21/11/2023 | 17/6/2026 | authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authentik) must check if there is a matching and existing `code_verifier` during the token step. Prior to versions 2023.10.4 and 2023.8.5,… | |
| Modificada | Media (5.3) | 0.70% | — | Nextauth.js Next-auth | 20/11/2023 | 17/6/2026 | NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization are affected by a vulnerability. A bad actor could create an empty/mock user, by getting hold of a NextAuth.js-issued JWT from an interrupted OAuth sign-in flow (state,… | |
| Modificada | Crítica (9.8) | 0.94% | — | Apereo Central Authentication Service | 9/11/2023 | 17/6/2026 | Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the… | |
| Modificada | Media (6.5) | 0.40% | — | Authzed Spicedb | 31/10/2023 | 17/6/2026 | SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.27.0-rc1, when the provided datastore URI is malformed (e.g. by having a password which contains `:`) the full URI (including the provided password) is printed, so that… | |
| Modificada | Crítica (9.8) | 0.65% | — | Goauthentik Authentik | 31/10/2023 | 17/6/2026 | authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any authentication. authentik uses a blueprint to create the default admin user, which… | |
| Modificada | Media (5.9) | 0.55% | — | Networknt Light-oauth2 | 25/10/2023 | 17/6/2026 | light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token. | |
| Modificada | Media (5.3) | 0.54% | — | Miniorange Google Authenticator | 20/10/2023 | 17/6/2026 | The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's settings. | |
| Modificada | Crítica (9.6) | 1.1% | — | Xwiki Oauth Identity | 16/10/2023 | 17/6/2026 | com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and XWiki syntax injection. This allows… | |
| Modificada | Media (5.3) | 0.52% | — | Webauthn4j Spring Security | 16/10/2023 | 17/6/2026 | WebAuthn4J Spring Security provides Web Authentication specification support for Spring applications. Affected versions are subject to improper signature counter value handling. A flaw was found in webauthn4j-spring-security-core. When an authneticator returns an incremented signature counter value during… |