Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.47% | — | Firebase AuthenticationAI | 22/8/2026 | 26/8/2026 | The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators. | |
| Aplazada | Alta (8.3) | 0.35% | — | BudibaseAIMongodbAIGoogle FirebaseAI | 13/8/2026 | 31/8/2026 | Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend… | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | Datadog Android ApplicationAIGoogle Firebase CrashlyticsAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems. | |
| Pendiente de análisis | Alta (8.5) | 0.35% | — | Google Cloud Firebase StudioAIGoogle Cloud PlatformAI | 17/7/2026 | 17/7/2026 | Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on 15 April 2026, and no customer action is… | |
| Aplazada | Alta (8.8) | 0.52% | — | Firebase Support Chat ManagementAI | 27/5/2026 | 17/6/2026 | The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This is due to the `firebase_auth()` function authenticating the request as the WordPress user whose email is supplied in the `user_email` POST parameter without verifying… | |
| Aplazada | Alta (8.2) | 0.43% | — | Google FirebaseAIWeb3formsAI | 12/3/2026 | 17/6/2026 | NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vulnerability was identified where Firebase and Web3Forms API keys were exposed. An attacker could use these keys to interact with backend services without authentication,… | |
| Aplazada | Alta (8.1) | 0.37% | — | Miniorange OTP Verification With FirebaseAI | 19/9/2025 | 17/6/2026 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in versions 3.1.0 to 3.6.2. This makes it possible for unauthenticated attackers to update the default role to Administrator.… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Genx FXAIGoogle CloudAIGoogle FirebaseAIGithubAI | 19/8/2025 | 17/6/2026 | GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and authentication tokens may be exposed if environment variables are misconfigured. Unauthorized users could gain access to cloud resources (Google Cloud, Firebase, GitHub,… | |
| Modificada | Media (6.5) | 0.14% | — | Google Firebase Php-jwt | 31/7/2025 | 17/6/2026 | php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an… | |
| Analizada | Media (4.3) | 0.14% | — | Skywavesolutions WP Firebase Push Notification | 4/7/2025 | 17/6/2026 | The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the wfpn_brodcast_notification_message() function. This makes it possible for unauthenticated attackers to send… | |
| Aplazada | Crítica (9.8) | 0.75% | — | Appgenix Infotech Firebase OTP AuthenticationAI | 13/12/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Appgenix Infotech Firebase OTP Authentication authentication-via-otp-using-firebase allows Authentication Bypass.This issue affects Firebase OTP Authentication: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.4) | 0.29% | — | Integrate FirebaseAI | 12/12/2024 | 17/6/2026 | The Integrate Firebase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'firebase_show' shortcode in all versions up to, and including, 0.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Media (5.2) | 0.13% | — | Google Firebase Javascript SDK | 18/11/2024 | 17/6/2026 | Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Miniorange OTP Verification With FirebaseAI | 17/10/2024 | 17/6/2026 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user… | |
| Analizada | Crítica (9.8) | 0.60% | — | Miniorange OTP Verification With Firebase | 17/10/2024 | 17/6/2026 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources, and the user current… | |
| Analizada | Alta (8.1) | 0.63% | — | Miniorange OTP Verification With Firebase | 17/10/2024 | 17/6/2026 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin. This makes it possible for unauthenticated attackers to log in as any… | |
| Aplazada | Crítica (9.8) | 1.2% | — | ARCAIGoogle FirebaseAI | 20/9/2024 | 17/6/2026 | Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary… | |
| Analizada | Media (4.3) | 0.13% | — | Google Firebase Command Line Interface | 2/5/2024 | 17/6/2026 | This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint that is used normally to export data from running emulators. If a user was running the emulator and navigated to a malicious website with the exploit on a browser that allowed calls to localhost (ie… | |
| Aplazada | Crítica (9.8) | 1.2% | — | Andrei-tatar Nora-firebase-commonAI | 18/4/2024 | 17/6/2026 | An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary code via a crafted script to the updateState parameter of the updateStateInternal method. | |
| Modificada | Crítica (9.1) | 0.79% | — | Google Firebase Php-jwt | 29/3/2022 | 17/6/2026 | In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. NOTE: this provides a straightforward way to use the PHP-JWT… | |
| Modificada | Media (5.3) | 0.57% | — | Google Firebase/util | 16/11/2020 | 17/6/2026 | This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program. | |
| Modificada | Crítica (9.8) | 1.2% | — | Icanstudioz Firebase Push Notification ON IOS / FCM + Advance Admin Panel | 10/7/2018 | 17/6/2026 | The "Firebase Cloud Messaging (FCM) + Advance Admin Panel" component supporting Firebase Push Notification on iOS (through 2017-10-26) allows SQL injection via the /advance_push/public/login username parameter. | |
| Modificada | Alta (8.1) | 1.3% | — | Firebase Admin SDK FOR PHP Project Firebase Admin SDK FOR PHP | 9/2/2018 | 17/6/2026 | Jerome Gamez Firebase Admin SDK for PHP version from 3.2.0 to 3.8.0 contains a Incorrect Access Control vulnerability in src/Firebase/Auth/IdTokenVerifier.php does not verify for token signature that can result in JWT with any email address and user ID could be forged from an actual token, or from thin air. This… |