Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

290 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.26%—Federico Rota Authentication AND Xmlrpc LOG WriterAI14/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Federico Rota Authentication and xmlrpc log writer authentication-and-xmlrpc-log-writer allows Reflected XSS.This issue affects Authentication and xmlrpc log writer: from n/a through <= 1.2.2.
AplazadaAlta (8.6)0.43%—Perl Catalyst Authentication Credential HttpAIPerl Data UuidAI11/8/202517/6/2026
—
AplazadaMedia (6.1)0.31%—Opentext Advanced AuthenticationAI6/8/202517/6/2026
A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the user authentication process to bypass Authentication. This issue affects Advanced Authentication on or before 6.5.0.
AplazadaCrítica (9.6)0.40%—Zscaler Saml AuthenticationAI5/8/202517/6/2026
An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse.
AnalizadaMedia (6.5)0.40%—Two-factor Authentication Project Two-factor Authentication8/7/202517/6/2026
Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0.
AplazadaBaja (2.3)0.50%—Ash-project ASH Authentication PhoenixAI17/6/202522/9/2026
Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards. The default sign_out/2 that AshAuthentication.Phoenix.Controller injects into an application's auth controller only calls Plug.Conn.clear_session/1. It…
AplazadaBaja (2.1)0.18%—Opentext Advanced AuthenticationAI27/5/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentication allows Information Elicitation. The vulnerability could reveal sensitive information while managing and configuring of the external services. This issue affects Advanced Authentication versions…
AplazadaCrítica (9.4)0.41%—Opentext Advanced AuthenticationAI14/5/202517/6/2026
Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5.
AplazadaAlta (7.5)0.29%—Opentext Advanced AuthenticationAI14/5/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5
AplazadaMedia (5.3)0.46%—Moodle Catalyst User KEY Authentication PluginAI10/5/202517/6/2026
A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affected by this vulnerability is an unknown functionality of the file /auth/userkey/logout.php of the component Logout. The manipulation of the argument return leads to open redirect. The attack can be…
AnalizadaMedia (5.3)0.64%—Apereo Central Authentication Service27/4/202517/6/2026
A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\core\cas-server-core-configuration-metadata-repository\src\main\java\org\apereo\cas\metadata\rest\CasConfigurationMetadataServerController.java. The manipulation of the…
AnalizadaMedia (5.1)0.62%—Apereo Central Authentication Service27/4/202517/6/2026
A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredServicesMultiActionController.java. The manipulation of the…
AnalizadaBaja (2.3)0.48%—Apereo Central Authentication Service27/4/202517/6/2026
A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSimpleFormController.java of the component Groovy Code Handler.…
AplazadaMedia (5.4)0.51%—Miniorange Wordpress Rest API AuthenticationAI16/4/202517/6/2026
Missing Authorization vulnerability in miniOrange WordPress REST API Authentication wp-rest-api-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress REST API Authentication: from n/a through <= 3.6.3.
AplazadaMedia (5.3)0.31%—Alembic ASH AuthenticationAI15/4/202517/6/2026
Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered by clicking a link sent via email. Some email clients and security tools (e.g., Outlook, virus scanners, and email previewers) may automatically follow these links,…
AnalizadaAlta (8.1)0.39%—Two-factor Authentication Project Two-factor Authentication31/3/202517/6/2026
Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0.
AplazadaMedia (6.9)0.40%—Centrify Authentication ServiceAI28/3/202517/6/2026
User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker to determine whether an email address is registered through specific error messages.
AplazadaCrítica (9.1)0.61%—Spid Aspnetcore AuthenticationAI18/2/202517/6/2026
SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: Identity Provider (IDP): the system that authenticates users and provides identity information (SAML affirmation) to the Service Provider, in…
AplazadaMedia (4.3)0.46%—RSA Authentication ManagerAI17/2/202517/6/2026
RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur.
AnalizadaMedia (6.3)0.31%—Alembic ASH Authentication11/2/202517/6/2026
Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have used the magic link strategy _or_ are manually revoking tokens are affected by revoked tokens being allowed to verify as…
AnalizadaAlta (8.8)0.55%—Jenkins Openid Connect Authentication22/1/202517/6/2026
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in…
AnalizadaAlta (7.3)0.32%—Basic Http Authentication Project Basic Http Authentication9/1/202517/6/2026
Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.
AnalizadaCrítica (9.8)0.46%—Two-factor Authentication Project Two-factor Authentication9/1/202517/6/2026
Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.
AnalizadaCrítica (9.8)0.64%—Rest & Json API Authentication Project Rest & Json API Authentication9/1/202517/6/2026
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.
AnalizadaCrítica (9.8)0.56%—Two-factor Authentication Project Two-factor Authentication9/1/202517/6/2026
Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0.