Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

6557 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.33%—Goauthentik AuthentikAI24/9/202624/9/2026
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected…
AplazadaAlta (8.8)0.51%💥 PoCGoauthentik AuthentikAI24/9/202628/9/2026
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group…
AplazadaAlta (8.9)0.49%—Goauthentik AuthentikAI24/9/20265/10/2026
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the setup request instead of using the address already established by the flow. An actor who knows a…
Pendiente de análisisMedia (4.3)0.24%—KeycloakAI24/9/202624/9/2026
A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This allows a delegated administrator with basic search privileges to view detailed…
AplazadaBaja (2.1)0.33%—Zoneland O2oaAI24/9/202624/9/2026
A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of the file o2server/x_base_core_project/src/main/java/com/x/base/core/project/connection/CipherConnectionAction.java of the component Cipher Connection Handler. Such manipulation of the argument fileUrl…
Pendiente de análisisMedia (6.6)0.24%—KeycloakAI24/9/202624/9/2026
A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting…
Pendiente de análisisMedia (4.2)0.17%—KeycloakAI24/9/202626/9/2026
A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations…
AplazadaAlta (7.6)0.29%—Easydigitaldownloads Easy Digital DownloadsAI23/9/202623/9/2026
Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.
AplazadaAlta (7.1)0.19%—Mangboard Mang Board WPAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.
Pendiente de análisisMedia (4.2)0.18%—KeycloakAI23/9/202626/9/2026
A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is already logged in. Due to this bypass, the security rule that ensures a pushed request…
Pendiente de análisisMedia (6.8)0.24%—KeycloakAI23/9/202624/9/2026
A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow…
AplazadaMedia (5.3)0.21%—FluentboardsAI23/9/202623/9/2026
The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, typically including administrators.
AplazadaCrítica (9)0.19%—WP Oauth ServerAI23/9/202624/9/2026
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and…
Pendiente de análisisMedia (6.8)0.19%—KeycloakAI22/9/202622/9/2026
A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without SPNEGO, the system fails to verify the identity of the Key Distribution Center (KDC) by requesting a server ticket. This allows an attacker on…
AplazadaMedia (5.5)0.41%—Yonyou KsoaAI21/9/202622/9/2026
A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for…
Pendiente de análisisBaja (3.1)0.31%—KeycloakAI21/9/202622/9/2026
A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authentication (2FA) setup, through a client policy. A user can bypass this requirement by…
Pendiente de análisisBaja (3.5)0.24%—KeycloakAI21/9/202624/9/2026
A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system incorrectly merges the permissions from both resources when one user requests an…
Pendiente de análisisMedia (5.5)0.30%—KeycloakAI21/9/202622/9/2026
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifying if the client belongs to the realm specified in the request path. This allows…
Pendiente de análisisMedia (4.9)0.39%—KeycloakAI21/9/202622/9/2026
A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies apply to specific users. Due to missing authorization checks, a delegated…
AplazadaAlta (7.1)0.55%—Qloapps QloapsAI19/9/202622/9/2026
QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including…
Pendiente de análisisMedia (6.5)0.44%—KeycloakAI19/9/202622/9/2026
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows a delegated administrator, who should be restricted from resetting passwords, to…
Pendiente de análisisMedia (6.6)0.40%—KeycloakAI19/9/202622/9/2026
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. This allows a delegated administrator with…
Pendiente de análisisMedia (4.2)0.23%—KeycloakAI19/9/202622/9/2026
A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client IDs. Keycloak fails to verify if the target audience client is still enabled before…
AplazadaMedia (6.5)0.41%—Download ManagerAI18/9/202618/9/2026
The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any…
AplazadaMedia (6.4)0.25%—Auto Upload ImagesAI18/9/202618/9/2026
The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations…