Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.26% | — | Progress Sitefinity Nextjs SDKAI | 5/10/2026 | 6/10/2026 | CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information. | |
| Analizada | Alta (7.6) | 0.43% | — | Clerk/astroClerk/backendClerk/chrome-extensionClerk/clerk-expo+13 | 11/5/2026 | 17/6/2026 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a… | |
| Aplazada | Crítica (9.1) | 0.53% | — | Clerk NextjsAIClerk NuxtAIClerk AstroAIClerk SharedAI | 24/4/2026 | 17/6/2026 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers. This vulnerability is fixed in @clerk/astro 1.5.7,… | |
| Analizada | Media (5.4) | 0.26% | — | Nextjs-auth0 | 17/4/2026 | 17/6/2026 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the proxy cache fetcher to perform improper lookups for the token request results. Users are affected if their project uses both… | |
| Analizada | Alta (7.7) | 0.44% | — | Opennextjs Opennext FOR Cloudflare | 4/3/2026 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, resulting from a path normalization bypass in the /cdn-cgi/image/ handler.The @opennextjs/cloudflare worker template includes a /cdn-cgi/image/ handler intended for development use only. In production, Cloudflare's… | |
| Analizada | Media (5.7) | 0.26% | — | Nextjs-auth0 | 11/12/2025 | 17/6/2026 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through 4.12.1 contain an input-validation flaw in the returnTo parameter, which could allow attackers to inject unintended OAuth query parameters into the Auth0 authorization request. Successful… | |
| Analizada | Media (5.4) | 0.20% | — | Nextjs-auth0 | 10/12/2025 | 25/9/2026 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and… | |
| Analizada | Alta (8) | 0.37% | — | Workos Authkit-nextjs | 21/11/2025 | 17/6/2026 | The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In authkit-nextjs version 2.11.0 and below, authenticated responses do not defensively apply anti-caching headers. In environments where CDN caching is enabled, this can result in… | |
| Analizada | Alta (7.8) | 0.97% | — | Create-cloudflareOpennextjs Opennext FOR Cloudflare | 16/6/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed unauthenticated users to proxy arbitrary remote content via the /_next/image endpoint. This issue allowed… | |
| Aplazada | Alta (7.7) | 0.43% | — | Nextjs-auth0AI | 4/6/2025 | 17/6/2026 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK versions 4.0.1 through 4.6.0, `__session` cookies set by auth0.middleware may be cached by CDNs due to missing Cache-Control headers. Three preconditions must be met in order for someone to be affected… | |
| Aplazada | Media (4.9) | 0.43% | — | Auth0 Nextjs SDKAI | 29/4/2025 | 17/6/2026 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie… | |
| Analizada | Baja (2.1) | 0.25% | — | Workos Authkit-nextjs | 5/11/2024 | 17/6/2026 | The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.13.2 and all users are… | |
| Analizada | Alta (8.1) | 0.66% | — | Workos Authkit-nextjs | 29/3/2024 | 17/6/2026 | The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session by controlling the `x-workos-session` header. The vulnerability is patched in v0.4.2. | |
| Modificada | Media (6.1) | 0.66% | — | Nextjs-auth0 | 16/12/2021 | 17/6/2026 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain returnTo parameter values from the login url, which expose the application to an open redirect vulnerability. Users are advised to upgrade as soon as possible. There are no… | |
| Modificada | Media (6.1) | 1.4% | — | Nextjs-auth0 | 25/6/2021 | 17/6/2026 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and including `1.4.1` are vulnerable to reflected XSS. An attacker can execute arbitrary code by providing an XSS payload in the `error` query parameter which is then processed by the callback handler as an… |