Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.37% | — | Aqara Cloud Oauth Authorization Endpoint | 12/6/2026 | 9/7/2026 | The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe Equivalence in Input" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N… | |
| Aplazada | Baja (2.3) | 0.35% | — | Authzed SpicedbAI | 10/6/2026 | 23/7/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper cache reuse. This issue has been patched in version 1.52.0. | |
| Analizada | Media (6.1) | 0.25% | — | Broadcom Spring Authorization ServerVmware Spring Security | 10/6/2026 | 23/7/2026 | Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability. Affected… | |
| Aplazada | Crítica (9.1) | 0.37% | — | Catalyst Plugin AuthenticationAI | 9/6/2026 | 21/7/2026 | Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim. | |
| Analizada | Crítica (9.8) | 0.58% | — | Goauthentik Authentik | 2/6/2026 | 22/7/2026 | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1. | |
| Analizada | Alta (8.8) | 0.44% | — | Goauthentik Authentik | 2/6/2026 | 22/7/2026 | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an account in one of the configured sources can log into any account. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1. | |
| Analizada | Alta (8.5) | 0.28% | — | Goauthentik Authentik | 2/6/2026 | 22/7/2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed assertion to authenticate… | |
| Analizada | Crítica (9.3) | 0.47% | — | Goauthentik Authentik | 2/6/2026 | 22/7/2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched… | |
| Analizada | Media (6.9) | 0.32% | — | Goauthentik Authentik | 2/6/2026 | 22/7/2026 | authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check rather than proper URL parsing. An attacker who can craft a login link can supply a wreply value on a different origin that passes the check… | |
| Analizada | Media (6.9) | 0.19% | — | Goauthentik Authentik | 2/6/2026 | 22/7/2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on assertions. NotBefore, NotOnOrAfter, and AudienceRestriction are all ignored. This allows replay of expired assertions and… | |
| Pendiente de análisis | Alta (7.5) | 0.65% | — | Cloudfoundry Cf-auth-proxyAICloudfoundry Log-cache ReleaseAI | 1/6/2026 | 22/7/2026 | Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token. Affected versions: -… | |
| Aplazada | Crítica (9.8) | 0.29% | — | SillytavernAIAutheliaAIGoauthentik AuthentikAI | 29/5/2026 | 22/7/2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and X-Authentik-Username (Authentik) HTTP headers to automatically log in… | |
| Aplazada | Alta (7.3) | 0.50% | — | Better-auth Better AuthAI | 28/5/2026 | 21/7/2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it received in x-forwarded-for (or the configured IP-bearing header). IPv6 clients controlling a typical /64 allocation could… | |
| Modificada | Media (6.1) | 0.29% | — | Authlib | 27/5/2026 | 17/6/2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by… | |
| Analizada | Media (4.3) | 0.33% | — | Jenkins Bitbucket Oauth | 27/5/2026 | 17/6/2026 | Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | |
| Analizada | Alta (7.1) | 0.29% | — | Auth0.js | 27/5/2026 | 17/6/2026 | Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is fixed in 10.0.0. | |
| Aplazada | Media (4.3) | 0.21% | — | Two-factor AuthenticationAI | 27/5/2026 | 17/6/2026 | The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the ipv_save_changes function. This makes it possible for unauthenticated attackers to modify the… | |
| Aplazada | Alta (8.1) | 0.72% | — | Goauthentik AuthentikAI | 22/5/2026 | 23/7/2026 | authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_superuser=True, without requiring… | |
| Aplazada | Alta (7.1) | 0.56% | — | Goauthentik AuthentikAI | 22/5/2026 | 23/7/2026 | authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the client_secret of confidential OAuth2 providers they have previously authenticated against, exposing sensitive information… | |
| Aplazada | Media (5.1) | 0.18% | — | Perl Catalyst Plugin AuthenticationAI | 21/5/2026 | 23/7/2026 | Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. | |
| Aplazada | Alta (7.5) | 0.49% | — | Authen TotpAI | 21/5/2026 | 23/7/2026 | Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage. | |
| Analizada | Media (6.5) | 0.77% | — | Powerdns Authoritative | 21/5/2026 | 23/7/2026 | Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail | |
| Analizada | Alta (7.5) | 0.58% | — | Powerdns Authoritative | 21/5/2026 | 23/7/2026 | Concurrency and locking defects in GSS-TSIG | |
| Analizada | Alta (7.5) | 0.80% | — | Powerdns Authoritative | 21/5/2026 | 23/7/2026 | Insufficient Validation of Autoprimary SOA Queries | |
| Analizada | Alta (8.6) | 0.54% | — | Powerdns Authoritative | 21/5/2026 | 23/7/2026 | Insufficient Validation of Names During AXFR |