Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1211 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.42% | — | Goauthentik AuthentikAI | 11/8/2026 | 3/9/2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SCIM group that matches an existing administrator group by name. The SCIM group ingest function adopts any existing group… | |
| Pendiente de análisis | Crítica (9.9) | 0.69% | — | Kuadrant AuthpolicyAIKubernetes ServiceaccountAI | 10/8/2026 | 27/8/2026 | A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain unauthorized… | |
| Aplazada | Media (4.4) | 0.12% | — | Estonian Information System Authority LibdigidocppAIEstonian Information System Authority Digidoc4AIEstonian Information System Authority Digidoc ON AndroidAIEstonian Information System Authority Digidoc ON IOSAI | 10/8/2026 | 1/9/2026 | Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before… | |
| Aplazada | Media (5.5) | 0.67% | — | Lmammino Oidc-authorizerAI | 9/8/2026 | 12/8/2026 | A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda Authorizer. The manipulation results in sensitive information in log files. The attack can be executed remotely. `src/handler.rs` logs raw Authorization header values… | |
| Aplazada | Media (5.5) | 0.64% | — | Lmammino Oidc-authorizerAI | 9/8/2026 | 12/8/2026 | A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_header of the file src/parse_token_from_header.rs of the component Authorization Header Parsing. The manipulation of the argument authorization_token leads to denial of service. Remote exploitation of the… | |
| Aplazada | Crítica (9.3) | 0.40% | — | WP Oauth ServerAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | |
| Aplazada | Media (6.5) | 0.18% | — | Miniorange Google AuthenticatorAI | 6/8/2026 | 26/8/2026 | The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account. | |
| Pendiente de análisis | Media (6.5) | 0.18% | — | Openshift Oauth-proxyAI | 5/8/2026 | 6/8/2026 | A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application without stripping them. An unauthenticated attacker can inject… | |
| Aplazada | Media (6.5) | 0.41% | — | Afthemes WP Post AuthorAI | 5/8/2026 | 12/8/2026 | The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the 'wpma_metabox_authors_list' parameter in all versions up to, and including, 3.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Google AuthAI | 4/8/2026 | 26/8/2026 | Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as `system($command)`, a single argument call that passes the whole string to… | |
| Aplazada | Alta (7.5) | 0.52% | — | Google AuthAI | 4/8/2026 | 26/8/2026 | Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read from the credentials JSON, and their hosts were not checked against the universe domain before the request. For an… | |
| Aplazada | Crítica (9.3) | 0.46% | — | Better-authAI | 2/8/2026 | 6/10/2026 | better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the server after startup can poison the router's base path, causing all routes to return 404 for all users (denial of… | |
| Aplazada | Alta (7.1) | 0.35% | — | Better-authAI | 2/8/2026 | 29/9/2026 | better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs… | |
| Pendiente de análisis | Alta (8.8) | 0.52% | — | Rou3AIBetter-auth Better AuthAI | 2/8/2026 | 6/10/2026 | Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass… | |
| Analizada | Alta (8.2) | 0.46% | — | Ueberauth Guardian | 1/8/2026 | 6/8/2026 | Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes the supplied token with peek/1, which performs no signature verification (it only base64-decodes the JWT header and… | |
| Analizada | Media (6.9) | 0.48% | — | Ueberauth Guardian | 1/8/2026 | 6/8/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via BEAM atom-table exhaustion. This vulnerability is associated with program file lib/guardian/permissions.ex and program routines… | |
| Analizada | Media (6.9) | 0.48% | — | Ueberauth Guardian | 1/8/2026 | 6/8/2026 | Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncoding encodes permission scopes by passing arbitrary binaries to String.to_atom/1. When encode/3 in… | |
| Analizada | Media (6.9) | 0.48% | — | Ueberauth Guardian | 1/8/2026 | 6/8/2026 | Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives connection and session namespace keys by passing arbitrary binaries to String.to_atom/1. base_key/1 in… | |
| Aplazada | Alta (7.1) | 0.46% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session caching. | |
| Aplazada | Crítica (9.4) | 0.24% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of… | |
| Aplazada | Media (6) | 0.28% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attacker's external… | |
| Aplazada | Media (5.1) | 0.32% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to maintain authentication for up to seven days after account deletion. | |
| Aplazada | Media (5.1) | 0.26% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp plugin (which wraps the same provider). An attacker can register an OAuth client with a javascript: redirect_uri, which the… | |
| Aplazada | Media (5.3) | 0.26% | — | Better-auth Oauth-providerAI | 1/8/2026 | 8/9/2026 | @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain access tokens whose audience targets resource servers the authorization never covered, bypassing… | |
| Aplazada | Alta (8.7) | 0.39% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the… |