Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.26% | — | Federico Rota Authentication AND Xmlrpc LOG WriterAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Federico Rota Authentication and xmlrpc log writer authentication-and-xmlrpc-log-writer allows Reflected XSS.This issue affects Authentication and xmlrpc log writer: from n/a through <= 1.2.2. | |
| Aplazada | Alta (8.6) | 0.43% | — | Perl Catalyst Authentication Credential HttpAIPerl Data UuidAI | 11/8/2025 | 17/6/2026 | — | |
| Aplazada | Media (6.1) | 0.31% | — | Opentext Advanced AuthenticationAI | 6/8/2025 | 17/6/2026 | A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the user authentication process to bypass Authentication. This issue affects Advanced Authentication on or before 6.5.0. | |
| Aplazada | Crítica (9.6) | 0.40% | — | Zscaler Saml AuthenticationAI | 5/8/2025 | 17/6/2026 | An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse. | |
| Analizada | Media (6.5) | 0.40% | — | Two-factor Authentication Project Two-factor Authentication | 8/7/2025 | 17/6/2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0. | |
| Aplazada | Baja (2.3) | 0.50% | — | Ash-project ASH Authentication PhoenixAI | 17/6/2025 | 22/9/2026 | Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards. The default sign_out/2 that AshAuthentication.Phoenix.Controller injects into an application's auth controller only calls Plug.Conn.clear_session/1. It… | |
| Aplazada | Baja (2.1) | 0.18% | — | Opentext Advanced AuthenticationAI | 27/5/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentication allows Information Elicitation. The vulnerability could reveal sensitive information while managing and configuring of the external services. This issue affects Advanced Authentication versions… | |
| Aplazada | Crítica (9.4) | 0.41% | — | Opentext Advanced AuthenticationAI | 14/5/2025 | 17/6/2026 | Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5. | |
| Aplazada | Alta (7.5) | 0.29% | — | Opentext Advanced AuthenticationAI | 14/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText Advanced Authentication. This issue affects Advanced Authentication versions before 6.5 | |
| Aplazada | Media (5.3) | 0.46% | — | Moodle Catalyst User KEY Authentication PluginAI | 10/5/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affected by this vulnerability is an unknown functionality of the file /auth/userkey/logout.php of the component Logout. The manipulation of the argument return leads to open redirect. The attack can be… | |
| Analizada | Media (5.3) | 0.64% | — | Apereo Central Authentication Service | 27/4/2025 | 17/6/2026 | A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\core\cas-server-core-configuration-metadata-repository\src\main\java\org\apereo\cas\metadata\rest\CasConfigurationMetadataServerController.java. The manipulation of the… | |
| Analizada | Media (5.1) | 0.62% | — | Apereo Central Authentication Service | 27/4/2025 | 17/6/2026 | A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredServicesMultiActionController.java. The manipulation of the… | |
| Analizada | Baja (2.3) | 0.48% | — | Apereo Central Authentication Service | 27/4/2025 | 17/6/2026 | A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSimpleFormController.java of the component Groovy Code Handler.… | |
| Aplazada | Media (5.4) | 0.51% | — | Miniorange Wordpress Rest API AuthenticationAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress REST API Authentication wp-rest-api-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress REST API Authentication: from n/a through <= 3.6.3. | |
| Aplazada | Media (5.3) | 0.31% | — | Alembic ASH AuthenticationAI | 15/4/2025 | 17/6/2026 | Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered by clicking a link sent via email. Some email clients and security tools (e.g., Outlook, virus scanners, and email previewers) may automatically follow these links,… | |
| Analizada | Alta (8.1) | 0.39% | — | Two-factor Authentication Project Two-factor Authentication | 31/3/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0. | |
| Aplazada | Media (6.9) | 0.40% | — | Centrify Authentication ServiceAI | 28/3/2025 | 17/6/2026 | User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker to determine whether an email address is registered through specific error messages. | |
| Aplazada | Crítica (9.1) | 0.61% | — | Spid Aspnetcore AuthenticationAI | 18/2/2025 | 17/6/2026 | SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: Identity Provider (IDP): the system that authenticates users and provides identity information (SAML affirmation) to the Service Provider, in… | |
| Aplazada | Media (4.3) | 0.46% | — | RSA Authentication ManagerAI | 17/2/2025 | 17/6/2026 | RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur. | |
| Analizada | Media (6.3) | 0.31% | — | Alembic ASH Authentication | 11/2/2025 | 17/6/2026 | Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have used the magic link strategy _or_ are manually revoking tokens are affected by revoked tokens being allowed to verify as… | |
| Analizada | Alta (8.8) | 0.55% | — | Jenkins Openid Connect Authentication | 22/1/2025 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in… | |
| Analizada | Alta (7.3) | 0.32% | — | Basic Http Authentication Project Basic Http Authentication | 9/1/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4. | |
| Analizada | Crítica (9.8) | 0.46% | — | Two-factor Authentication Project Two-factor Authentication | 9/1/2025 | 17/6/2026 | Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0. | |
| Analizada | Crítica (9.8) | 0.64% | — | Rest & Json API Authentication Project Rest & Json API Authentication | 9/1/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13. | |
| Analizada | Crítica (9.8) | 0.56% | — | Two-factor Authentication Project Two-factor Authentication | 9/1/2025 | 17/6/2026 | Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0. |