Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2773▼ 299 respecto a la semana anterior
Críticas / altas1298▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

6574 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.36%—A3 Lazy LoadAI28/5/202617/6/2026
The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.6 This is due to a regex bug in the _filter_videos() method that breaks HTML attribute quoting when processing crafted <video> elements, combined with unescaped output in the…
ModificadaMedia (5.3)0.72%—Redhat Build OF Keycloak28/5/202626/6/2026
A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration endpoint. This can lead to an ArrayIndexOutOfBoundsException, causing…
ModificadaMedia (6.8)0.52%—Redhat Build OF Keycloak28/5/202626/6/2026
A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been revoked. Successful…
ModificadaMedia (4.9)0.90%—Redhat Build OF Keycloak28/5/202626/6/2026
A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password policy response…
ModificadaMedia (4.3)0.49%—Redhat Build OF Keycloak28/5/202620/8/2026
A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection.…
AplazadaMedia (4.3)0.20%—Easydigitaldownloads Easy Digital DownloadsAI28/5/202617/6/2026
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init` hook and processes Square OAuth tokens from a…
ModificadaMedia (6.5)0.38%—Redhat Build OF Keycloak28/5/202615/9/2026
A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them…
ModificadaAlta (7.3)0.49%—Redhat Build OF Keycloak28/5/202615/7/2026
A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a client's scope mapping. This bypasses intended security controls, allowing the…
ModificadaMedia (5.3)0.57%💥 PoCRedhat Build OF Keycloak28/5/202626/6/2026
A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker…
ModificadaAlta (7.5)0.26%—Redhat Build OF Keycloak28/5/202620/8/2026
A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of…
ModificadaMedia (6.5)0.46%—Redhat Build OF Keycloak28/5/202626/6/2026
A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently bypassed. This allows an…
ModificadaMedia (4.3)0.37%—Redhat Build OF Keycloak28/5/202626/6/2026
A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disclosed in tokens, even after…
AnalizadaMedia (4.3)0.33%—Jenkins Bitbucket Oauth27/5/202617/6/2026
Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
AnalizadaMedia (5.6)0.18%—Broadcom Rabbitmq Server27/5/202617/6/2026
RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.
AnalizadaMedia (5.3)0.20%—Broadcom Rabbitmq Server27/5/202617/6/2026
RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create patterns such as ^{client_id}-sensors$ to restrict user access to topics that include their client ID.…
ModificadaAlta (8.8)0.59%—Redhat Build OF Keycloak27/5/202626/6/2026
A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fall back to client credentials. This…
ModificadaMedia (4.2)0.43%—Redhat Build OF Keycloak27/5/202620/8/2026
A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the…
AplazadaMedia (6.5)0.38%—Wpwham Checkout Files UploadAI27/5/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout Files Upload for WooCommerce: from n/a through <= 2.2.5.
AplazadaAlta (8.7)0.54%—SsoabstractserviceAI27/5/202617/6/2026
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
AplazadaMedia (4.3)0.29%—Yoast SEOAI27/5/202624/7/2026
El plugin Yoast SEO para WordPress es vulnerable a Referencias Inseguras a Objetos Directos en todas las versiones hasta la 26.5, inclusive. Esto se debe a comprobaciones de autorización insuficientes en el endpoint de la API REST de Meta Search que no verifican la propiedad de las publicaciones. Esto hace posible que…
AplazadaBaja (2.3)0.35%—ThingsboardAI26/5/202623/7/2026
Se ha identificado una debilidad en ThingsBoard hasta la versión 4.3.1.1. Afectada por esta vulnerabilidad es la función getGatewayDockerComposeFile del archivo /API/v1/provision del componente YAML Gestor. Esta manipulación causa inyección de código. Es posible iniciar el ataque de forma remota. La complejidad del…
Pendiente de análisisMedia (5.5)0.61%—KOA RouterAI26/5/202623/7/2026
Las versiones del paquete @koa/router desde la 14.0.0 y anteriores a la 15.0.0 son vulnerables a una omisión de control de acceso debido a que el middleware se elimina silenciosamente de la cadena de ejecución cuando el prefijo del router contiene parámetros de ruta. Dependiendo de lo que el middleware omitido debía…
AplazadaAlta (7.2)0.41%—Videowhisper Broadcast Live VideoAI25/5/202624/7/2026
Control inadecuado de la generación de código ('Inyección de código') vulnerabilidad en VideoWhisper.Com Broadcast Live Video permite la inyección de código. Este problema afecta a Broadcast Live Video: desde n/a antes de 7.1.3.
AplazadaBaja (2.1)0.40%—Dazeb Markdown-downloaderAI25/5/202623/7/2026
Se ha encontrado una vulnerabilidad en dazeb markdown-downloader hasta 3d4394b34b6c99d81af817623af55e3384df5a6a. La función download_markdown/list_downloaded_files/create_subdirectory del archivo src/index.ts está afectada. La ejecución de una manipulación puede conducir a un salto de ruta. El ataque puede lanzarse de…
AplazadaAlta (8.1)0.72%—Goauthentik AuthentikAI22/5/202623/7/2026
authentik es un proveedor de identidad de código abierto. En versiones anteriores a la 2025.12.5 y de la 2026.2.0-rc1 a la 2026.2.2, la API PATCH /api/v3/core/users/{pk}/ permite a un llamador con 'change_user' sobre un usuario objetivo asignar grupos arbitrarios a través de UserSerializer, incluyendo grupos con…