Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1211 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.72% | — | Apache Http ServerAIMOD Auth OpenidcAI | 21/8/2026 | 18/9/2026 | mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is… | |
| Aplazada | Alta (8.4) | 0.19% | — | Estonian Information System Authority Digidoc4AI | 20/8/2026 | 1/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client. This issue affects DigiDoc4: from 4.0.0 before 4.11.0. | |
| Aplazada | Media (5.7) | 0.50% | — | Punk Oauth2AI | 20/8/2026 | 28/8/2026 | Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter. oauth2_login reads the return parameter from the initiation request, runs same_origin_path over it, and stores the survivor in the session flow… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | RSA Securid Authentication ManagerAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial parameter is not masked and is shown in… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Crowdstrike Oauth API APP FOR Splunk SoarAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password parameter is not masked and is shown in… | |
| Aplazada | Alta (7.5) | 0.51% | — | NET OauthAI | 19/8/2026 | 26/8/2026 | Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally computed one with the eq operator, which returns as soon as the two strings differ. The time… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Atlassian OauthAI | 19/8/2026 | 26/8/2026 | Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to check a signature is chosen by whoever… | |
| Aplazada | Alta (8.8) | 0.62% | — | Goauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings that can contain stored credentials. The… | |
| Aplazada | Crítica (9.4) | 0.59% | — | Goauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity provider's signed assertion. An attacker with an account on the source… | |
| Aplazada | Media (5.3) | 0.44% | — | Goauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization filter used by the rest of the API. Any party able to reach the API, including an unauthenticated client, can invoke the diagnostic action… | |
| Aplazada | Alta (8.6) | 0.68% | — | Google ChromeAIGoogle Verified Access APIAIGoauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED… | |
| Aplazada | Media (6.5) | 0.55% | — | Atlassian OauthAI | 16/8/2026 | 26/8/2026 | Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash with no bound and no eviction, and keeps an entry for every class name it is asked about, including names that failed to load, because… | |
| Aplazada | Crítica (9.8) | 0.72% | — | Digitialpixies Oauth ClientAI | 16/8/2026 | 26/8/2026 | Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the constructor selects OAuth 1.0a. get_request_token then revokes that choice when the request token response omits oauth_callback_confirmed, with no… | |
| Analizada | Media (5.4) | 0.10% | — | Fastify/oauth2 | 15/8/2026 | 4/9/2026 | @fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefixed, predictable cookie, with no server-side binding to the browser that began the… | |
| Aplazada | Crítica (9.8) | 0.84% | — | Dancer2 Plugin Auth ExtensibleAI | 15/8/2026 | 26/8/2026 | Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes from the request Host header, or from… | |
| Pendiente de análisis | Crítica (9.1) | 0.64% | — | Nextauth.js Next-authAI | 13/8/2026 | 18/9/2026 | NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.js has a server configuration error. In middleware, Route Handlers, React Server… | |
| Pendiente de análisis | Crítica (9.1) | 0.73% | — | Nextauth.js Next-authAICoreAI | 13/8/2026 | 18/9/2026 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an address before applying Unicode normalization. An address can contain a Unicode character such as U+FF20 FULLWIDTH… | |
| Pendiente de análisis | Media (4.7) | 0.28% | — | Backstage Plugin-auth-backendAILinuxfoundation BackstageAI | 13/8/2026 | 18/9/2026 | Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching for… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Digitialpixies Oauth ClientAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. | |
| Aplazada | Alta (7.4) | 0.49% | — | Auth-fetch-mcpAI | 13/8/2026 | 18/9/2026 | auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `assertSafeUrl()` (`src/security.ts`) to block requests to private and loopback addresses. However, the `isPrivateV6()` function fails to detect IPv4-mapped IPv6 loopback… | |
| Aplazada | Alta (8.8) | 0.47% | — | Cedar Policy Authorization FOR ExpressjsAIExpressAI | 13/8/2026 | 9/9/2026 | @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. Versions prior to 0.3.0 have an issue where, under certain… | |
| Pendiente de análisis | Media (6.8) | 0.25% | — | Nextauth.js Next-authAICoreAI | 12/8/2026 | 9/9/2026 | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value minted during a… | |
| Pendiente de análisis | Alta (7.5) | 0.88% | — | Nextauth @auth/coreAINextauth.js Next-authAI | 12/8/2026 | 9/9/2026 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a malformed Authorization: Bearer header. When no session cookie is present,… | |
| Pendiente de análisis | Media (4.3) | 0.36% | — | Oauth-serverAI | 11/8/2026 | 14/8/2026 | A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled… | |
| Aplazada | Alta (8.8) | 0.40% | — | Goauthentik AuthentikAI | 11/8/2026 | 3/9/2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts… |