Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.34% | — | Wp-oauth WP Oauth Server | 5/12/2022 | 17/6/2026 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID | |
| Modificada | Media (4.8) | 0.51% | — | Wp-oauth WP Oauth Server | 5/12/2022 | 17/6/2026 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.2 does not sanitize and escape Client IDs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 1.3% | — | Goauthentik Authentik | 2/12/2022 | 17/6/2026 | authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can create new accounts in authentik. If a flow exists that allows for email-verified password recovery,… | |
| Modificada | Media (6.5) | 0.36% | — | Digitialpixies Oauth Client | 14/11/2022 | 17/6/2026 | The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions. | |
| Modificada | Media (4.8) | 0.53% | — | Digitialpixies Oauth Client | 14/11/2022 | 17/6/2026 | The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Alta (7.5) | 0.44% | — | Oauth Client Single Sign ON Project Oauth Client Single Sign ON | 26/9/2022 | 17/6/2026 | The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email… | |
| Modificada | Media (6.5) | 1.7% | — | Oauthlib Project OauthlibFedoraproject Fedora | 9/9/2022 | 17/6/2026 | OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` functions depending where it is used. OAuthLib applications using… | |
| Modificada | Alta (7.2) | 0.97% | — | Oauth2-server Project Oauth2-server | 29/8/2022 | 17/6/2026 | In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern ("[a-zA-Z][a-zA-Z0-9+.-]+:") before making a redirection. This allows a malicious client to pass an XSS payload through the… | |
| Modificada | Crítica (9.8) | 1.8% | — | Miniorange Oauth 2.0 Client FOR SSO | 22/8/2022 | 17/6/2026 | Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress. | |
| Modificada | Crítica (9.8) | 1.3% | — | Miniorange WP Oauth Server | 22/8/2022 | 17/6/2026 | Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codexshaper WP Oauth2 Server | 22/7/2022 | 17/6/2026 | Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress. | |
| Modificada | Media (5.3) | 1.2% | — | Miniorange Oauth Single Sign ON | 17/7/2022 | 17/6/2026 | The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address. | |
| Modificada | Media (6.1) | 0.83% | — | Apifest Oauth 2.0 Server | 29/6/2022 | 17/6/2026 | ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an open redirector attack. Specifically, it directly sends an authorization code to the redirect URI submitted with the authorization request, without checking whether the redirect URI is registered by… | |
| Modificada | Media (6.5) | 0.47% | — | Jupyter Oauthenticator | 9/6/2022 | 17/6/2026 | OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of… | |
| Modificada | Alta (7.3) | 0.30% | — | Google Oauth Client Library FOR Java | 3/5/2022 | 17/6/2026 | The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An attacker can provide a compromised token with custom payload. The token will pass the validation on the client side. We… | |
| Modificada | Media (6.5) | 1.3% | — | Pivotal Spring Security OauthOracle Communications Design Studio | 21/4/2022 | 17/6/2026 | <Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. A malicious user or attacker can send multiple requests initiating the… | |
| Modificada | Media (6.1) | 0.72% | — | Broadcom Layer7 API Management Oauth Toolkit | 18/2/2022 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a remote attacker to craft a malicious URL for the OTK web UI and target OTK users with phishing attacks or other social engineering techniques. A successful attack allows injecting malicious code into… | |
| Modificada | Media (6.1) | 0.56% | — | Scratchoauth2 Project Scratchoauth2 | 15/2/2022 | 17/6/2026 | A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request. | |
| Modificada | Crítica (10) | 1.1% | — | Scratchoauth2 Project Scratchoauth2 | 15/2/2022 | 17/6/2026 | An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components that rely on ScratchOAuth2. | |
| Modificada | Media (6.5) | 0.64% | — | Scratchoauth2 Project Scratchoauth2 | 15/2/2022 | 17/6/2026 | An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps. | |
| Modificada | Media (5.3) | 1.3% | — | Passportjs Passport-oauth2 | 27/9/2021 | 17/6/2026 | The passport-oauth2 package before 1.6.1 for Node.js mishandles the error condition of failure to obtain an access token. This is exploitable in certain use cases where an OAuth identity provider uses an HTTP 200 status code for authentication-failure error reports, and an application grants authorization upon simply… | |
| Modificada | Media (6.8) | 0.81% | — | Scratchoauth2 Project Scratchoauth2 | 13/4/2021 | 17/6/2026 | ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable by a user can be read and modified by a third party. 1. Scratch user visits 3rd party site. 2. 3rd party site asks user for Scratch username. 3. 3rd party site pretends to be user and gets login code… | |
| Modificada | Media (5.5) | 1.1% | — | Oauth2 Proxy Project Oauth2 Proxy | 26/3/2021 | 17/6/2026 | OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group-based authorization in the GitLab provider stopped working in the v7.0.0 release. Regardless of the flag settings, authorization wasn't restricted. Additionally, any… | |
| Modificada | Media (6.1) | 1.6% | — | Oauth2 Proxy Project Oauth2 Proxy | 2/2/2021 | 17/6/2026 | OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain or group. In OAuth2 Proxy before version 7.0.0, for users that use the whitelist domain feature, a domain that ended in a similar way to… | |
| Modificada | Media (6.3) | 1.1% | — | Jupyter Oauthenticator | 1/12/2020 | 17/6/2026 | OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2) configuration `Authenticator.whitelist`, which should be transparently mapped to `Authenticator.allowed_users` with a warning, is instead ignored by OAuthenticator… |