Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.13%—Dash10 Oauth ServerAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
AplazadaCrítica (9)0.19%—WP Oauth ServerAI23/9/202624/9/2026
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and…
Pendiente de análisisAlta (7.5)0.63%—Openshift Oauth-serverAIGolang.org X TextAI1/9/20261/9/2026
A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the…
AplazadaAlta (7.5)0.26%—WP Oauth ServerAI27/8/202628/8/2026
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including…
Pendiente de análisisMedia (4.3)0.36%—Oauth-serverAI11/8/202614/8/2026
A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled…
AplazadaCrítica (9.3)0.40%—WP Oauth ServerAI6/8/202612/8/2026
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
AplazadaMedia (4.9)0.37%—Oauth-serverAI15/11/202426/6/2026
A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug higher for OIDC/GitHub/GitLab/Google IDPs login options.
ModificadaMedia (6.1)0.38%—Wp-oauth WP Oauth Server10/4/202417/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3.
ModificadaMedia (4.3)0.26%—Dash10 Oauth Server20/3/202317/6/2026
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
ModificadaMedia (4.3)0.25%—Dash10 Oauth Server20/3/202317/6/2026
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.
ModificadaMedia (6.5)0.33%—Wp-oauth WP Oauth Server5/12/202217/6/2026
The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID
ModificadaMedia (4.8)0.49%—Wp-oauth WP Oauth Server5/12/202217/6/2026
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.2 does not sanitize and escape Client IDs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaCrítica (9.8)1.3%—Miniorange WP Oauth Server22/8/202217/6/2026
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
ModificadaCrítica (9.8)2.1%—Dash10 Oauth Server26/9/201917/6/2026
The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.