Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.60%—Microchip Cryptoauthlib22/10/202017/6/2026
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 1 of 2).
ModificadaMedia (6.8)0.60%—Microchip Cryptoauthlib22/10/202017/6/2026
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 2 of 2).
ModificadaAlta (7.5)2.2%—Oauth2-server Project Oauth2-server4/10/202017/6/2026
oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As RFC7636 is an extension, I think the claim in the Readme of "RFC 6749 compliant" is valid and not misleading and I also…
ModificadaAlta (7.4)0.86%—Oauth-ruby Project Oauth-ruby24/9/202017/6/2026
lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certificate bundle cannot be found, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
ModificadaCrítica (9.1)1.6%—Google Oauth Client Library FOR Java9/7/202017/6/2026
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able…
ModificadaMedia (5.4)0.90%—Oauth2 Proxy Project Oauth2 Proxy29/6/202017/6/2026
In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is expected to be the original URL that the user was trying to access. This redirect URL is checked within the proxy and…
ModificadaMedia (6.1)0.79%—Oauth2 Proxy Project Oauth2 Proxy7/5/202017/6/2026
In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is expected to be the original URL that the user was trying to access. This redirect URL is checked within the proxy…
ModificadaCrítica (9.8)2.4%—Omniauth-weibo-oauth2 Project Omniauth-weibo-oauth27/2/202017/6/2026
The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.
ModificadaMedia (6.1)1.3%—Oauth2 Proxy Project Oauth2 Proxy30/1/202017/6/2026
OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.
ModificadaAlta (7.8)0.33%—Jenkins Bitbucket Oauth23/10/201917/6/2026
Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
ModificadaMedia (6.5)0.99%—Jenkins Google Oauth Credentials16/10/201917/6/2026
An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master.
ModificadaCrítica (9.8)2.1%—Dash10 Oauth Server26/9/201917/6/2026
The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
ModificadaAlta (8.8)1.2%—Schine.games Mw-oauth2client19/8/201917/6/2026
In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function.
ModificadaMedia (6.1)0.97%—Jenkins Gitlab Oauth7/8/201917/6/2026
An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins after successful login.
ModificadaAlta (7.5)1.3%—Jenkins Gitlab Oauth7/8/201917/6/2026
A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.
ModificadaMedia (5.4)8.9%💥 ExploitPivotal Software Spring Security OauthOracle Banking Corporate Lending12/6/201917/6/2026
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint…
ModificadaMedia (6.5)17%💥 ExploitPivotal Software Spring Security OauthOracle Banking Corporate Lending7/3/201917/6/2026
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization…
ModificadaMedia (5.9)0.85%—Jenkins Github Oauth6/2/201917/6/2026
An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.
ModificadaMedia (4.3)1.1%—Jenkins Github Oauth6/2/201917/6/2026
An exposure of sensitive information vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client…
ModificadaAlta (8.1)2.2%—Pivotal Software Spring Security Oauth18/10/201817/6/2026
Spring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to 2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0.16, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can craft a request to the approval endpoint that can modify…
ModificadaMedia (6.1)0.91%—Oauth2orize-fprm Project Oauth2orize-fprm17/6/201817/6/2026
index.js in oauth2orize-fprm before 0.2.1 has XSS via a crafted URL.
ModificadaCrítica (9.8)11%💥 PoCPivotal Software Spring Security Oauth11/5/201817/6/2026
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code…
ModificadaAlta (8.8)1.8%—Jupyter Oauthenticator18/2/201817/6/2026
An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were…
ModificadaMedia (6.1)72%💥 ExploitAtlassian Oauth23/8/201717/6/2026
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).
ModificadaMedia (6.1)1.00%—Oauth2 Proxy Project Oauth2 Proxy17/7/201717/6/2026
The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819
Orbitaley — Vulnerabilidades