Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.25% | — | Dancer2 Plugin Auth Oauth ProviderAI | 4/7/2026 | 6/7/2026 | Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting token into the… | |
| Aplazada | Alta (8.1) | 0.23% | — | Plack Middleware OauthAI | 4/7/2026 | 6/7/2026 | Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without… | |
| Aplazada | Media (5.1) | 0.18% | — | Liboauth2AI | 2/7/2026 | 2/7/2026 | In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the… | |
| Aplazada | Media (5.1) | 0.17% | — | Liboauth2AI | 2/7/2026 | 2/7/2026 | liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to alb_base_url without URL encoding or path sanitization, and the HTTP GET is… | |
| Aplazada | Media (5.3) | 0.40% | — | Secufor OauthAI | 24/6/2026 | 25/6/2026 | The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to disconnect the WordPress site from its linked… | |
| Aplazada | Crítica (9.1) | 0.52% | — | Mojolicious Plugin WEB Auth Oauth2AI | 23/6/2026 | 23/6/2026 | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header)… | |
| Aplazada | Crítica (9.1) | 0.33% | — | Dancer2 Plugin Auth OauthAI | 15/6/2026 | 17/6/2026 | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable. | |
| Analizada | Media (6.1) | 0.37% | — | Aqara Cloud Oauth Authorization Endpoint | 12/6/2026 | 9/7/2026 | The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe Equivalence in Input" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N… | |
| Analizada | Crítica (9.8) | 0.58% | — | Goauthentik Authentik | 2/6/2026 | 22/7/2026 | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1. | |
| Analizada | Alta (8.8) | 0.44% | — | Goauthentik Authentik | 2/6/2026 | 22/7/2026 | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in one of the configured sources can log into any account. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1. | |
| Analizada | Alta (8.5) | 0.28% | — | Goauthentik Authentik | 2/6/2026 | 22/7/2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed assertion to authenticate… | |
| Analizada | Crítica (9.3) | 0.47% | — | Goauthentik Authentik | 2/6/2026 | 22/7/2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched… | |
| Analizada | Media (6.9) | 0.32% | — | Goauthentik Authentik | 2/6/2026 | 22/7/2026 | authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check rather than proper URL parsing. An attacker who can craft a login link can supply a wreply value on a different origin that passes the check… | |
| Analizada | Media (6.9) | 0.19% | — | Goauthentik Authentik | 2/6/2026 | 22/7/2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on assertions. NotBefore, NotOnOrAfter, and AudienceRestriction are all ignored. This allows replay of expired assertions and… | |
| Aplazada | Crítica (9.8) | 0.29% | — | SillytavernAIAutheliaAIGoauthentik AuthentikAI | 29/5/2026 | 22/7/2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and X-Authentik-Username (Authentik) HTTP headers to automatically log in… | |
| Analizada | Media (4.3) | 0.33% | — | Jenkins Bitbucket Oauth | 27/5/2026 | 17/6/2026 | Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | |
| Aplazada | Alta (8.1) | 0.72% | — | Goauthentik AuthentikAI | 22/5/2026 | 23/7/2026 | authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_superuser=True, without requiring… | |
| Aplazada | Alta (7.1) | 0.56% | — | Goauthentik AuthentikAI | 22/5/2026 | 23/7/2026 | authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the client_secret of confidential OAuth2 providers they have previously authenticated against, exposing sensitive information… | |
| Aplazada | Alta (8.7) | 0.68% | — | Goauthentik AuthentikAI | 21/5/2026 | 23/7/2026 | authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it was possible for an attacker to trick… | |
| Aplazada | Crítica (10) | 0.58% | — | Openvpn-auth-oauth2AI | 8/5/2026 | 17/6/2026 | openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the experimental plugin mode (shared library loaded by OpenVPN via the plugin directive), clients… | |
| Analizada | Alta (7.1) | 0.37% | — | Better-auth/oauth-provider | 24/4/2026 | 17/6/2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option documents a create action, but the OAuth client creation endpoints did not invoke the hook before persisting new clients. Deployments that configured clientPrivileges to restrict client registration… | |
| Analizada | Media (5.9) | 0.35% | — | Node-oauth/oauth2-server | 23/4/2026 | 17/6/2026 | @node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKCE flows. Because short/weak verifiers are accepted and failed verifier attempts do not consume the authorization code,… | |
| Analizada | Alta (8.2) | 0.43% | — | Oauth2 Proxy Project Oauth2 Proxy | 22/4/2026 | 17/6/2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of patterns that can be… | |
| Modificada | Crítica (9.1) | 0.73% | — | Oauth2 Proxy Project Oauth2 Proxy | 22/4/2026 | 15/7/2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route` is configured. An attacker can spoof this header so OAuth2 Proxy… | |
| Analizada | Media (6.8) | 0.34% | — | Oauth2 Proxy Project Oauth2 Proxy | 21/4/2026 | 17/6/2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain enforcement option. An attacker may be able to authenticate with an email claim such as attacker@evil.com@company.com and satisfy an allowed… |