Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.2% | — | Goauthentik Authentik | 21/11/2023 | 17/6/2026 | authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authentik) must check if there is a matching and existing `code_verifier` during the token step. Prior to versions 2023.10.4 and 2023.8.5,… | |
| Modificada | Crítica (9.8) | 0.65% | — | Goauthentik Authentik | 31/10/2023 | 17/6/2026 | authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any authentication. authentik uses a blueprint to create the default admin user, which… | |
| Modificada | Media (5.9) | 0.55% | — | Networknt Light-oauth2 | 25/10/2023 | 17/6/2026 | light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token. | |
| Modificada | Crítica (9.6) | 1.1% | — | Xwiki Oauth Identity | 16/10/2023 | 17/6/2026 | com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and XWiki syntax injection. This allows… | |
| Modificada | Media (4.8) | 0.40% | — | Stormconsultancy Oauth Twitter Feed FOR Developers | 1/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy (Storm Consultancy) oAuth Twitter Feed for Developers plugin <= 2.3.0 versions. | |
| Modificada | Media (5.3) | 0.62% | — | Goauthentik Authentik | 29/8/2023 | 17/6/2026 | goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage an attacker is able to determine if a username exists. Only setups configured with a recovery flow are impacted by this. Anyone with a user account on a system with the recovery flow described above… | |
| Modificada | Alta (8.8) | 0.96% | 💥 PoC | Miniorange Oauth Single Sign ON | 18/7/2023 | 17/6/2026 | Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3. | |
| Modificada | Alta (7.3) | 0.79% | — | Goauthentik Authentik | 6/7/2023 | 17/6/2026 | authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the source of the X-Forwarded-For and X-Real-IP headers, both in the Python code and the go code. Only authentik setups that are directly accessible by users without a reverse proxy are susceptible to… | |
| Modificada | Alta (7.5) | 0.95% | — | Thephpleague Oauth2-server | 6/7/2023 | 17/6/2026 | league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2 and prior to version 8.5.3, servers that passed their keys to the CryptKey constructor as as string instead of a file path will have had that key included in a LogicException message if they did not… | |
| Modificada | Alta (8.8) | 0.70% | — | Fastify Oauth2 | 4/7/2023 | 17/6/2026 | All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all requests for all users. The purpose of the Oauth2 state parameter is to prevent Cross-Site-Request-Forgery attacks. As such, it should be unique per user and should be connected to the user's session in… | |
| Modificada | Media (5.4) | 0.32% | — | Jenkins Wso2 Oauth | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the attacker's account. | |
| Modificada | Media (5.4) | 0.43% | — | Jenkins Wso2 Oauth | 16/5/2023 | 17/6/2026 | Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login. | |
| Modificada | Media (6.5) | 0.40% | — | Jenkins Wso2 Oauth | 12/4/2023 | 17/6/2026 | Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it. | |
| Modificada | Media (4.3) | 0.32% | — | Jenkins Wso2 Oauth | 12/4/2023 | 17/6/2026 | Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (6.5) | 0.33% | — | Miniorange Oauth Single Sign ON | 27/3/2023 | 17/6/2026 | The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack | |
| Modificada | Media (6.5) | 0.44% | — | Miniorange Oauth Single Sign ON | 27/3/2023 | 17/6/2026 | The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP),… | |
| Modificada | Media (4.3) | 0.26% | — | Dash10 Oauth Server | 20/3/2023 | 17/6/2026 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client. | |
| Modificada | Media (4.3) | 0.25% | — | Dash10 Oauth Server | 20/3/2023 | 17/6/2026 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack. | |
| Modificada | Media (6.5) | 0.27% | — | Goauthentik Authentik | 4/3/2023 | 17/6/2026 | authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created by an admin (or sent via email by an admin) can be used to set the password for any arbitrary user. This attack is only possible if a recovery flow exists, which has both an Identification and an… | |
| Modificada | Media (5.7) | 0.48% | — | Jenkins Bitbucket Oauth | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account. | |
| Modificada | Crítica (9.8) | 1.1% | — | Jenkins Bitbucket Oauth | 26/1/2023 | 17/6/2026 | Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login. | |
| Modificada | Media (6.4) | 0.54% | — | Goauthentik Authentik | 28/12/2022 | 17/6/2026 | authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticated user can create an arbitrary number of accounts through the default flows. This would circumvent any policy in a situation where it is undesirable for users to create… | |
| Modificada | Alta (8.8) | 0.88% | — | Goauthentik Authentik | 28/12/2022 | 17/6/2026 | authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via the use of a different enrollment flow than in the one provided. The vulnerability… | |
| Modificada | Crítica (9.1) | 0.85% | — | Digitalocean Golang-nanoauth | 27/12/2022 | 17/6/2026 | Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token. | |
| Modificada | Crítica (9.8) | 14% | — | Logrocket-oauth2-example Project Logrocket-oauth2-example | 14/12/2022 | 17/6/2026 | logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter. |