Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
6557 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.33% | — | Goauthentik AuthentikAI | 24/9/2026 | 24/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected… | |
| Aplazada | Alta (8.8) | 0.51% | 💥 PoC | Goauthentik AuthentikAI | 24/9/2026 | 28/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group… | |
| Aplazada | Alta (8.9) | 0.49% | — | Goauthentik AuthentikAI | 24/9/2026 | 5/10/2026 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the setup request instead of using the address already established by the flow. An actor who knows a… | |
| Pendiente de análisis | Media (4.3) | 0.24% | — | KeycloakAI | 24/9/2026 | 24/9/2026 | A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This allows a delegated administrator with basic search privileges to view detailed… | |
| Aplazada | Baja (2.1) | 0.33% | — | Zoneland O2oaAI | 24/9/2026 | 24/9/2026 | A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of the file o2server/x_base_core_project/src/main/java/com/x/base/core/project/connection/CipherConnectionAction.java of the component Cipher Connection Handler. Such manipulation of the argument fileUrl… | |
| Pendiente de análisis | Media (6.6) | 0.24% | — | KeycloakAI | 24/9/2026 | 24/9/2026 | A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting… | |
| Pendiente de análisis | Media (4.2) | 0.17% | — | KeycloakAI | 24/9/2026 | 26/9/2026 | A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations… | |
| Aplazada | Alta (7.6) | 0.29% | — | Easydigitaldownloads Easy Digital DownloadsAI | 23/9/2026 | 23/9/2026 | Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. | |
| Aplazada | Alta (7.1) | 0.19% | — | Mangboard Mang Board WPAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions. | |
| Pendiente de análisis | Media (4.2) | 0.18% | — | KeycloakAI | 23/9/2026 | 26/9/2026 | A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is already logged in. Due to this bypass, the security rule that ensures a pushed request… | |
| Pendiente de análisis | Media (6.8) | 0.24% | — | KeycloakAI | 23/9/2026 | 24/9/2026 | A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow… | |
| Aplazada | Media (5.3) | 0.21% | — | FluentboardsAI | 23/9/2026 | 23/9/2026 | The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, typically including administrators. | |
| Aplazada | Crítica (9) | 0.19% | — | WP Oauth ServerAI | 23/9/2026 | 24/9/2026 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and… | |
| Pendiente de análisis | Media (6.8) | 0.19% | — | KeycloakAI | 22/9/2026 | 22/9/2026 | A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without SPNEGO, the system fails to verify the identity of the Key Distribution Center (KDC) by requesting a server ticket. This allows an attacker on… | |
| Aplazada | Media (5.5) | 0.41% | — | Yonyou KsoaAI | 21/9/2026 | 22/9/2026 | A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for… | |
| Pendiente de análisis | Baja (3.1) | 0.31% | — | KeycloakAI | 21/9/2026 | 22/9/2026 | A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authentication (2FA) setup, through a client policy. A user can bypass this requirement by… | |
| Pendiente de análisis | Baja (3.5) | 0.24% | — | KeycloakAI | 21/9/2026 | 24/9/2026 | A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system incorrectly merges the permissions from both resources when one user requests an… | |
| Pendiente de análisis | Media (5.5) | 0.30% | — | KeycloakAI | 21/9/2026 | 22/9/2026 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifying if the client belongs to the realm specified in the request path. This allows… | |
| Pendiente de análisis | Media (4.9) | 0.39% | — | KeycloakAI | 21/9/2026 | 22/9/2026 | A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies apply to specific users. Due to missing authorization checks, a delegated… | |
| Aplazada | Alta (7.1) | 0.55% | — | Qloapps QloapsAI | 19/9/2026 | 22/9/2026 | QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including… | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | KeycloakAI | 19/9/2026 | 22/9/2026 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows a delegated administrator, who should be restricted from resetting passwords, to… | |
| Pendiente de análisis | Media (6.6) | 0.40% | — | KeycloakAI | 19/9/2026 | 22/9/2026 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. This allows a delegated administrator with… | |
| Pendiente de análisis | Media (4.2) | 0.23% | — | KeycloakAI | 19/9/2026 | 22/9/2026 | A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client IDs. Keycloak fails to verify if the target audience client is still enabled before… | |
| Aplazada | Media (6.5) | 0.41% | — | Download ManagerAI | 18/9/2026 | 18/9/2026 | The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any… | |
| Aplazada | Media (6.4) | 0.25% | — | Auto Upload ImagesAI | 18/9/2026 | 18/9/2026 | The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations… |