Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

1212 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.24%—Heiglandreas Authldap6/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Andreas Heigl authLdap plugin <= 2.5.8 versions.
ModificadaAlta (8.8)0.26%—Remove/hide Author, Date, Category Like Entry-meta Project Remove/hide Author, Date, Category Like Entry-meta6/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Remove/hide Author, Date, Category Like Entry-Meta plugin <= 2.1 versions.
ModificadaMedia (6.1)0.45%—Broadpeak Centralized Accounts Management Auth Agent3/10/202317/6/2026
A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00.19219575_ee9195b0, 01.01.01.30097902_fd999e76, and 00.12.01.9565588_1254b459 allows remote attackers to inject arbitrary web script or HTML via the…
ModificadaAlta (8.8)0.23%—Yasglobal Http Auth3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui HTTP Auth plugin <= 0.3.2 versions.
ModificadaAlta (8.8)0.44%—Mekshq Meks Audio PlayerMekshq Meks Easy ADS WidgetMekshq Meks Easy MapsMekshq Meks Easy Photo Feed Widget+63/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the…
AnalizadaMedia (4.8)0.37%—Heiglandreas Authldap29/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Andreas Heigl authLdap plugin <= 2.5.9 versions.
ModificadaMedia (6.5)0.55%—Powauth POW18/9/202317/6/2026
Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` is susceptible to session hijacking as expired keys are not being invalidated correctly on startup. A session may expire when all…
ModificadaAlta (7.3)0.20%—Samsung Memory Card & UFD Authentication18/9/202317/6/2026
A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows to exploit this vulnerability.)
ModificadaAlta (8.8)0.66%—Jenkins Assembla Auth6/9/202317/6/2026
Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.
ModificadaMedia (5.5)0.17%—IBM Sterling External Authentication Server5/9/202317/6/2026
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing during operations. IBM X-Force ID: 252139.
ModificadaMedia (5.5)0.19%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy5/9/202317/6/2026
IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585.
ModificadaMedia (4.8)0.40%—Stormconsultancy Oauth Twitter Feed FOR Developers1/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy (Storm Consultancy) oAuth Twitter Feed for Developers plugin <= 2.3.0 versions.
AnalizadaAlta (7.5)1.3%⚠ Explotación activaKNX Connection Authorization29/8/202316/7/2026
KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not…
ModificadaMedia (5.3)0.62%—Goauthentik Authentik29/8/202317/6/2026
goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage an attacker is able to determine if a username exists. Only setups configured with a recovery flow are impacted by this. Anyone with a user account on a system with the recovery flow described above…
ModificadaMedia (5.5)0.14%—Thalesgroup Safenet Authentication Service16/8/202317/6/2026
Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via local privilege escalation.
ModificadaMedia (5.9)0.59%—Jenkins Tuleap Authentication16/8/202317/6/2026
Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.
ModificadaMedia (4.3)0.53%—Webfactoryltd Simple Author BOX14/8/202317/6/2026
The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that user, leading to arbitrary user information disclosure to users with a role as low as Contributor.
ModificadaMedia (6.1)0.38%—Wpkube Authors List27/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPKube Authors List plugin <= 2.0.2 versions.
ModificadaMedia (5.4)0.70%—Jenkins Gitlab Authentication26/7/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker's account.
ModificadaAlta (8.8)0.96%💥 PoCMiniorange Oauth Single Sign ON18/7/202317/6/2026
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
ModificadaMedia (6.5)0.48%—DUO Authentication Proxy12/7/202317/6/2026
A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability exists because certain unencrypted credentials are stored. An attacker could exploit this vulnerability by…
ModificadaBaja (3.3)0.29%—Fortinet FortiauthenticatorFortinet Fortios11/7/202317/6/2026
A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to…
ModificadaAlta (7.3)0.79%—Goauthentik Authentik6/7/202317/6/2026
authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the source of the X-Forwarded-For and X-Real-IP headers, both in the Python code and the go code. Only authentik setups that are directly accessible by users without a reverse proxy are susceptible to…
ModificadaAlta (7.5)0.95%—Thephpleague Oauth2-server6/7/202317/6/2026
league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2 and prior to version 8.5.3, servers that passed their keys to the CryptKey constructor as as string instead of a file path will have had that key included in a LogicException message if they did not…
ModificadaAlta (8.8)0.70%—Fastify Oauth24/7/202317/6/2026
All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all requests for all users. The purpose of the Oauth2 state parameter is to prevent Cross-Site-Request-Forgery attacks. As such, it should be unique per user and should be connected to the user's session in…
Orbitaley — Vulnerabilidades