Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1211 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.48% | — | AuthorizerAI | 2/9/2026 | 2/9/2026 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | |
| Aplazada | Alta (8.1) | 0.38% | — | Miniorange Oauth Single Sign ONAI | 2/9/2026 | 3/9/2026 | The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts. | |
| Aplazada | Alta (7.5) | 0.75% | — | Cleverange AuthAI | 1/9/2026 | 3/9/2026 | An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Openshift Oauth-serverAIGolang.org X TextAI | 1/9/2026 | 6/10/2026 | A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the… | |
| Pendiente de análisis | Media (6.5) | 0.32% | — | Apache HttpdAIDogtag Certificate AuthorityAIRedhat Identity ManagementAI | 1/9/2026 | 1/9/2026 | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion… | |
| Pendiente de análisis | Alta (8.7) | 1.5% | — | Yast2 Auth ClientAI | 1/9/2026 | 2/9/2026 | A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the configured host. Auth::AuthConf in src/lib/auth/authconf.rb assembles the Samba net ads join, net ads lookup -S and net ads testjoin invocations… | |
| Aplazada | Media (5.4) | 0.19% | — | Hono Oauth-providersAI | 31/8/2026 | 9/9/2026 | @hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the… | |
| Aplazada | Baja (1.9) | 0.15% | — | Extension.vn 2FA Authenticator ExtensionAI | 31/8/2026 | 2/9/2026 | A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is the function chrome.runtime.onMessageExternal.addListener of the component Background Service Worker. Executing a manipulation of the argument sender.id can lead to information disclosure. The attack… | |
| Aplazada | Media (5.1) | 0.41% | — | RodauthAI | 29/8/2026 | 11/9/2026 | Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift window to bypass the second authentication factor. | |
| Aplazada | Media (5.1) | 0.41% | — | RodauthAI | 29/8/2026 | 11/9/2026 | Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via non-POST methods to obtain a new valid access token, enabling indefinite account access with… | |
| Aplazada | Media (4.9) | 0.18% | — | RodauthAI | 29/8/2026 | 11/9/2026 | Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to… | |
| Aplazada | Media (4.9) | 0.33% | — | RodauthAI | 29/8/2026 | 11/9/2026 | Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browsers resolve as protocol-relative URLs, redirecting authenticated… | |
| Aplazada | Crítica (9.4) | 0.61% | — | RodauthAI | 29/8/2026 | 11/9/2026 | Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of validating the credential binding to… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Auth0 JsonwebtokenAIOmnivoreAI | 29/8/2026 | 24/9/2026 | The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jsonwebtoken v8 (which… | |
| Analizada | Alta (8.2) | 0.32% | — | Broadcom Spring Authorization Server | 27/8/2026 | 31/8/2026 | Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page… | |
| Analizada | Media (6.1) | 0.24% | — | Broadcom Spring Authorization Server | 27/8/2026 | 1/9/2026 | In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an… | |
| Aplazada | Alta (7.5) | 0.26% | — | WP Oauth ServerAI | 27/8/2026 | 28/8/2026 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including… | |
| Aplazada | Alta (8.6) | 0.36% | — | Better-auth SSOAI | 26/8/2026 | 24/9/2026 | @better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an authenticated organization… | |
| Aplazada | Baja (2.1) | 0.75% | — | Alembic ASH AuthenticationAI | 25/8/2026 | 1/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction forms. When a strategy is configured with require_interaction? set to true, AshAuthentication serves an intermediate… | |
| Aplazada | Alta (7.6) | 0.58% | — | Alembic ASH AuthenticationAI | 25/8/2026 | 1/9/2026 | Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The bearer-token authentication helper AshAuthentication.Plug.Helpers.retrieve_from_bearer/3 verifies an… | |
| Aplazada | Crítica (9.1) | 0.70% | — | Cakephp AuthenticationAICakephpAI | 24/8/2026 | 9/9/2026 | CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy… | |
| Aplazada | Crítica (9.3) | 0.45% | — | Oauth2 ProxyAI | 24/8/2026 | 24/9/2026 | OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever… | |
| Aplazada | Crítica (10) | 0.41% | — | Miniorange Oauth ClientAIMiniorange Oauth Single Sign ON Oidc SSOAIMiniorange Login With Keycloak Oauth Single Sign ON SSOAIMiniorange Single Sign ON FOR Educational InstitutesAI | 24/8/2026 | 8/9/2026 | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The manipulation of a cookie value allows actors to login as arbitrary… | |
| Aplazada | Crítica (9.1) | 0.50% | — | Punk Oauth2 ServerAI | 22/8/2026 | 26/8/2026 | Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registration. token dispatches on the grant_type in… | |
| Aplazada | Alta (8.1) | 0.47% | — | Firebase AuthenticationAI | 22/8/2026 | 26/8/2026 | The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators. |