Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.2%—Goauthentik Authentik21/11/202317/6/2026
authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authentik) must check if there is a matching and existing `code_verifier` during the token step. Prior to versions 2023.10.4 and 2023.8.5,…
ModificadaCrítica (9.8)0.65%—Goauthentik Authentik31/10/202317/6/2026
authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any authentication. authentik uses a blueprint to create the default admin user, which…
ModificadaMedia (5.9)0.55%—Networknt Light-oauth225/10/202317/6/2026
light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.
ModificadaCrítica (9.6)1.1%—Xwiki Oauth Identity16/10/202317/6/2026
com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and XWiki syntax injection. This allows…
ModificadaMedia (4.8)0.40%—Stormconsultancy Oauth Twitter Feed FOR Developers1/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy (Storm Consultancy) oAuth Twitter Feed for Developers plugin <= 2.3.0 versions.
ModificadaMedia (5.3)0.62%—Goauthentik Authentik29/8/202317/6/2026
goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage an attacker is able to determine if a username exists. Only setups configured with a recovery flow are impacted by this. Anyone with a user account on a system with the recovery flow described above…
ModificadaAlta (8.8)0.96%💥 PoCMiniorange Oauth Single Sign ON18/7/202317/6/2026
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
ModificadaAlta (7.3)0.79%—Goauthentik Authentik6/7/202317/6/2026
authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the source of the X-Forwarded-For and X-Real-IP headers, both in the Python code and the go code. Only authentik setups that are directly accessible by users without a reverse proxy are susceptible to…
ModificadaAlta (7.5)0.95%—Thephpleague Oauth2-server6/7/202317/6/2026
league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2 and prior to version 8.5.3, servers that passed their keys to the CryptKey constructor as as string instead of a file path will have had that key included in a LogicException message if they did not…
ModificadaAlta (8.8)0.70%—Fastify Oauth24/7/202317/6/2026
All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all requests for all users. The purpose of the Oauth2 state parameter is to prevent Cross-Site-Request-Forgery attacks. As such, it should be unique per user and should be connected to the user's session in…
ModificadaMedia (5.4)0.32%—Jenkins Wso2 Oauth16/5/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the attacker's account.
ModificadaMedia (5.4)0.43%—Jenkins Wso2 Oauth16/5/202317/6/2026
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
ModificadaMedia (6.5)0.40%—Jenkins Wso2 Oauth12/4/202317/6/2026
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it.
ModificadaMedia (4.3)0.32%—Jenkins Wso2 Oauth12/4/202317/6/2026
Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
ModificadaMedia (6.5)0.33%—Miniorange Oauth Single Sign ON27/3/202317/6/2026
The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack
ModificadaMedia (6.5)0.44%—Miniorange Oauth Single Sign ON27/3/202317/6/2026
The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP),…
ModificadaMedia (4.3)0.26%—Dash10 Oauth Server20/3/202317/6/2026
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
ModificadaMedia (4.3)0.25%—Dash10 Oauth Server20/3/202317/6/2026
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.
ModificadaMedia (6.5)0.27%—Goauthentik Authentik4/3/202317/6/2026
authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created by an admin (or sent via email by an admin) can be used to set the password for any arbitrary user. This attack is only possible if a recovery flow exists, which has both an Identification and an…
ModificadaMedia (5.7)0.48%—Jenkins Bitbucket Oauth26/1/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.
ModificadaCrítica (9.8)1.1%—Jenkins Bitbucket Oauth26/1/202317/6/2026
Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
ModificadaMedia (6.4)0.54%—Goauthentik Authentik28/12/202217/6/2026
authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would circumvent any policy in a situation where it is undesirable for users to create…
ModificadaAlta (8.8)0.88%—Goauthentik Authentik28/12/202217/6/2026
authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via the use of a different enrollment flow than in the one provided. The vulnerability…
ModificadaCrítica (9.1)0.85%—Digitalocean Golang-nanoauth27/12/202217/6/2026
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.
ModificadaCrítica (9.8)14%—Logrocket-oauth2-example Project Logrocket-oauth2-example14/12/202217/6/2026
logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.
Orbitaley — Vulnerabilidades