Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
1211 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.52% | — | Next-tinacms-azureAISupabase AuthAI | 16/9/2026 | 30/9/2026 | Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any… | |
| Pendiente de análisis | Alta (8.1) | 0.47% | — | Fastify AuthAI | 16/9/2026 | 17/9/2026 | @fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are composed with the relation "or" option together with the run "all" option and one entry is a nested array acting as an AND group, the… | |
| Pendiente de análisis | Media (4.3) | 0.33% | — | Jenkins Keycloak Authentication PluginAI | 16/9/2026 | 18/9/2026 | Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | |
| Aplazada | Media (6.9) | 0.38% | — | Miniorange JWT Authentication FOR WP Rest ApisAI | 15/9/2026 | 24/9/2026 | miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification.… | |
| Aplazada | Media (5.4) | 0.24% | — | Publishpress AuthorsAI | 15/9/2026 | 15/9/2026 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up to, and including, 4.15.0 due to insufficient input sanitization and output… | |
| Pendiente de análisis | Baja (3.7) | 0.34% | — | Authzed SpicedbAI | 14/9/2026 | 30/9/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or PERMISSIONSHIP_NO_PERMISSION because checkRequestToKey() and… | |
| Pendiente de análisis | Media (6.5) | 0.51% | — | Auth0 SymfonyAISymfonyAI | 14/9/2026 | 30/9/2026 | Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query parameter as well as the Authorization… | |
| Aplazada | Crítica (9.3) | 0.46% | — | AuthorizerAI | 11/9/2026 | 30/9/2026 | Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server appends `access_token`, `id_token`, and… | |
| Aplazada | Alta (8.7) | 0.87% | — | Macropay-solutions Maravel-frameworkAITymon Jwt-authAILaravelAI | 8/9/2026 | 10/9/2026 | Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-performance relational caching layers. Any application with low cache memory that… | |
| Pendiente de análisis | Alta (7.8) | 0.20% | — | Auth0 AD Ldap ConnectorAI | 8/9/2026 | 10/9/2026 | The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account. | |
| Pendiente de análisis | Crítica (9) | 0.40% | — | Auth0 AD Ldap ConnectorAI | 8/9/2026 | 10/9/2026 | The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the… | |
| Pendiente de análisis | Media (6.7) | 0.18% | — | Auth0 AD Ldap ConnectorAI | 8/9/2026 | 10/9/2026 | The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints,… | |
| Aplazada | Media (6.5) | 0.28% | — | React Native Auth0AI | 8/9/2026 | 10/9/2026 | The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. Under the listed preconditions, tokens cached in module memory can be retrieved… | |
| Aplazada | Alta (8.8) | 0.67% | — | CmsimpleAICmsimple CoauthorsAI | 8/9/2026 | 9/9/2026 | A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing crafted external or uploaded text content through the affected content import feature. | |
| Analizada | Alta (8.6) | 0.44% | — | Microsoft Authenticator | 8/9/2026 | 24/9/2026 | Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally. | |
| Aplazada | Media (6.3) | 0.69% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret/3 in AshAuthentication.Oauth2Server (reached through __resolve_secret__!) treated… | |
| Aplazada | Media (6.3) | 0.66% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy… | |
| Aplazada | Media (6.3) | 0.68% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlug and RequireScopePlug built the Bearer resource_metadata="..." challenge by… | |
| Aplazada | Media (6.3) | 0.66% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients. The RFC 8414 and RFC 9728 metadata endpoints in AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter return… | |
| Aplazada | Media (6.3) | 0.69% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the… | |
| Aplazada | Alta (8.2) | 0.66% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database storage and memory. The /authorize endpoint is unauthenticated by design. With Client ID Metadata Documents enabled, resolve_client/3 in… | |
| Aplazada | Crítica (9.8) | 0.31% | — | Mojox AuthenticationAINET Saml2AI | 6/9/2026 | 8/9/2026 | MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or anchors argument, then passes… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Authen Sasl Perl Digest MD5AI | 6/9/2026 | 8/9/2026 | Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing later compares that value against the nonce the client returns. server_step derives the expected… | |
| Aplazada | Alta (7.5) | 0.34% | — | Hivepress AuthenticationAI | 6/9/2026 | 8/9/2026 | The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to… | |
| Analizada | Media (5.4) | 0.30% | — | External Authentication Project External Authentication | 2/9/2026 | 15/9/2026 | Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13. |