Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.50% | — | 2fauth | 3/7/2023 | 17/6/2026 | 2FA is a Web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Cross site scripting (XSS) injection can be done via the account/service field. This was tested in docker-compose environment. This vulnerability has been patched in version 4.0.3. | |
| Modificada | Alta (7.5) | 0.50% | — | Apereo Central Authentication Service | 27/6/2023 | 17/6/2026 | Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake or a special HTTP header, such as “ssl_client_cert”. When checking the validity of the provided… | |
| Modificada | Media (5.3) | 0.45% | — | Authzed Spicedb | 26/6/2023 | 17/6/2026 | SpiceDB es un sistema de base de datos de código abierto, inspirado en Google Zanzibar, para crear y gestionar permisos de aplicaciones críticos para la seguridad. Cualquier usuario que tome una decisión de autorización negativa basada en los resultados de una solicitud "LookupResources" con la versión 1.22.0 se ve… | |
| Modificada | Media (5.4) | 0.32% | — | Jenkins Wso2 Oauth | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the attacker's account. | |
| Modificada | Media (5.4) | 0.43% | — | Jenkins Wso2 Oauth | 16/5/2023 | 17/6/2026 | Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Reverse Proxy Auth | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials. | |
| Modificada | Media (4.8) | 0.37% | — | Usbmemorydirect Simple Custom Author Profiles | 9/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in USB Memory Direct Simple Custom Author Profiles plugin <= 1.0.0 versions. | |
| Modificada | Media (4.8) | 0.50% | — | WP Custom Author URL Project WP Custom Author URL | 2/5/2023 | 17/6/2026 | The WP Custom Author URL WordPress plugin before 1.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (8.8) | 0.62% | — | Hypr Keycloak Authenticator | 28/4/2023 | 17/6/2026 | Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, before 8.0.3. | |
| Modificada | Alta (7.5) | 0.76% | — | Authzed Spicedb | 14/4/2023 | 17/6/2026 | SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. The `spicedb serve` command contains a flag named `--grpc-preshared-key` which is used to protect the gRPC API from being accessed by unauthorized requests. The values of this flag… | |
| Modificada | Media (5.3) | 1.0% | — | Sync Oxygen Content FusionSync Oxygen XML WEB Author | 14/4/2023 | 17/6/2026 | A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714 and 23.1.1.4 build 2023021715 are also… | |
| Modificada | Media (6.5) | 0.40% | — | Jenkins Wso2 Oauth | 12/4/2023 | 17/6/2026 | Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it. | |
| Modificada | Media (4.3) | 0.32% | — | Jenkins Wso2 Oauth | 12/4/2023 | 17/6/2026 | Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (6.1) | 0.49% | — | Fortinet Fortiauthenticator | 11/4/2023 | 17/6/2026 | An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected cross site scripting (XSS) attack via the "reset-password"… | |
| Modificada | Media (4.6) | 0.25% | — | Cisco DUOCisco DUO Authentication FOR Windows Logon AND RDP | 5/4/2023 | 17/6/2026 | A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected macOS or Windows device. This vulnerability… | |
| Analizada | Alta (7.5) | 1.3% | — | MOD Auth Openidc | 3/4/2023 | 17/6/2026 | mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when `OIDCStripCookies` is set and a crafted cookie supplied, a NULL pointer dereference would occur, resulting in a… | |
| Modificada | Crítica (9.8) | 0.83% | — | Jenkins Role-based Authorization Strategy | 2/4/2023 | 17/6/2026 | Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled. | |
| Modificada | Media (4.3) | 0.40% | — | Cloudfoundry User Account AND Authentication | 28/3/2023 | 17/6/2026 | This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an external identity provider is linked to the UAA, a refresh token is issued to a client on behalf of a user from that identity provider, the administrator of the UAA deactivates the identity provider… | |
| Modificada | Alta (8.8) | 0.80% | — | Mk-auth | 28/3/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file. | |
| Modificada | Media (6.5) | 0.33% | — | Miniorange Oauth Single Sign ON | 27/3/2023 | 17/6/2026 | The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack | |
| Modificada | Media (6.5) | 0.44% | — | Miniorange Oauth Single Sign ON | 27/3/2023 | 17/6/2026 | The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP),… | |
| Modificada | Media (6.1) | 0.43% | — | Twofactorauth Project Twofactorauth | 25/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Arno0x TwoFactorAuth. This affects an unknown part of the file login/login.php. The manipulation of the argument from leads to open redirect. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about… | |
| Modificada | Media (4.3) | 0.26% | — | Dash10 Oauth Server | 20/3/2023 | 17/6/2026 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client. | |
| Modificada | Media (4.3) | 0.25% | — | Dash10 Oauth Server | 20/3/2023 | 17/6/2026 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack. | |
| Analizada | Crítica (9.8) | 0.86% | — | Microfocus Netiq Advanced Authentication | 15/3/2023 | 17/6/2026 | Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2 |