Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.18% | — | Mskcc Oauth2 Client | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal OAuth2 Client allows Cross Site Request Forgery.This issue affects OAuth2 Client: from 0.0.0 before 4.1.3. | |
| Analizada | Alta (8) | 0.39% | — | Goauthentik Authentik | 28/3/2025 | 17/6/2026 | authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-default setting), deleting sessions via the Web Interface or the API would not revoke the session and the session holder would continue to have… | |
| Analizada | Media (4.8) | 0.30% | — | Goauthentik Authentik | 4/2/2025 | 17/6/2026 | Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release. | |
| Aplazada | Alta (8.8) | 0.71% | — | GoauthAI | 28/1/2025 | 17/6/2026 | Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected credentials stored in the users .netrc file. | |
| Analizada | Media (6.1) | 0.25% | — | Miniorange Oauth & Openid Connect Single Sign-on | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows Cross-Site Scripting (XSS).This issue affects OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client): from 3.0.0 before 3.44.0,… | |
| Aplazada | Media (6.3) | 0.46% | — | Guzzle Oauth SubscriberAI | 6/1/2025 | 17/6/2026 | Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used. This vulnerability is fixed in 0.8.1. | |
| Aplazada | Media (5.3) | 0.61% | — | NET OauthAI | 3/1/2025 | 17/6/2026 | In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong. | |
| Aplazada | Alta (8.1) | 0.79% | — | Oauth SSOAI | 12/12/2024 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.26.3. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any… | |
| Analizada | Media (6.3) | 0.55% | — | Goauthentik Authentik | 21/11/2024 | 17/6/2026 | authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ endpoint it was possible to brute-force the SECRET_KEY, which is used to authenticate the endpoint. The /-/metrics/ endpoint returns Prometheus metrics and is not intended to be accessed directly, as… | |
| Modificada | Alta (7.9) | 1.1% | — | Goauthentik Authentik | 21/11/2024 | 17/6/2026 | authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured in a provider, authentik will automatically use the first redirect_uri value received as an allowed redirect URI, without escaping characters that have… | |
| Analizada | Media (6.4) | 0.58% | — | Goauthentik Authentik | 21/11/2024 | 17/6/2026 | authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue. | |
| Aplazada | Media (4.9) | 0.37% | — | Oauth-serverAI | 15/11/2024 | 26/6/2026 | A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug higher for OIDC/GitHub/GitLab/Google IDPs login options. | |
| Analizada | Media (6.5) | 0.42% | — | Goauthentik Authentik | 27/9/2024 | 17/6/2026 | authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a user can steal an access token they were legitimately issued for one application… | |
| Analizada | Crítica (9) | 0.57% | — | Goauthentik Authentik | 27/9/2024 | 17/6/2026 | authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an unparsable IP address, e.g. `a`. This results in a possibility of logging into any account with a known login or email address.… | |
| Analizada | Alta (7.5) | 0.48% | — | Goauthentik Authentik | 22/8/2024 | 17/6/2026 | authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs/<uuid>/view_certificate/, /api/v3/crypto/certificatekeypairs/<uuid>/view_private_key/, and… | |
| Aplazada | Media (6.5) | 0.24% | — | Atlassian OauthAI | 15/8/2024 | 17/6/2026 | In the OAuth library for nim prior to version 0.11, the Authorization Code grant and Implicit grant both rely on the `state` parameter to prevent cross-site request forgery (CSRF) attacks where a resource owner might have their session associated with protected resources belonging to an attacker. When this project is… | |
| Aplazada | Media (6.5) | 0.25% | — | Atlassian OauthAI | 15/8/2024 | 17/6/2026 | In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not have sufficient entropy. These can be successfully guessed by an attacker allowing them to perform a CSRF vs a user, associating the user's session with the attacker's protected resources. While… | |
| Analizada | Crítica (9.8) | 0.58% | — | Goauthentik Authentik | 28/6/2024 | 17/6/2026 | authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens for an application and access it. This issue has been patched in version(s)… | |
| Analizada | Alta (8.8) | 0.76% | — | Goauthentik Authentik | 28/6/2024 | 17/6/2026 | authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik application, including resetting user… | |
| Aplazada | Alta (8.1) | 0.40% | — | JupyterhubAIJupyter OauthenticatorAI | 12/6/2024 | 17/6/2026 | OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be configured to allow all users from a particular institution only. This worked fine prior to JupyterHub 5.0, because `allow_all` did not take… | |
| Modificada | Media (6.1) | 0.38% | — | Wp-oauth WP Oauth Server | 10/4/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3. | |
| Analizada | Crítica (9.1) | 0.59% | — | Jupyter Oauthenticator | 20/3/2024 | 17/6/2026 | OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's own Authenticators with any OAuth 2.0 provider. `GoogleOAuthenticator.hosted_domain` is used to restrict what Google accounts can be authorized access to a JupyterHub. The restriction is intented to… | |
| Modificada | Alta (8.8) | 0.54% | — | Goauthentik Authentik | 30/1/2024 | 17/6/2026 | Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE offers. PKCE adds the code_challenge parameter to the authorization request and adds the code_verifier parameter to the token request. Prior to 2023.8.7 and… | |
| Modificada | Media (5.4) | 0.55% | — | Goauthentik Authentik | 11/1/2024 | 17/6/2026 | Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with `response_mode=form_post`. This relatively user could use the described attacks to perform a privilege escalation. This vulnerability has been… | |
| Modificada | Media (6.1) | 0.56% | — | Owncloud Oauth2 | 21/11/2023 | 17/6/2026 | An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently allows an attacker to redirect callbacks to a Top Level Domain controlled by the attacker. |