Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.30% | — | Oauth Single Sign ON SSOAI | 30/9/2026 | 30/9/2026 | Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. | |
| Aplazada | Alta (8.1) | 0.38% | — | Miniorange Oauth Single Sign ONAI | 2/9/2026 | 3/9/2026 | The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts. | |
| Aplazada | Crítica (10) | 0.41% | — | Miniorange Oauth ClientAIMiniorange Oauth Single Sign ON Oidc SSOAIMiniorange Login With Keycloak Oauth Single Sign ON SSOAIMiniorange Single Sign ON FOR Educational InstitutesAI | 24/8/2026 | 8/9/2026 | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The manipulation of a cookie value allows actors to login as arbitrary… | |
| Aplazada | Crítica (9.8) | 0.73% | — | Miniorange Oauth Single Sign ON - SSOAI | 10/7/2026 | 21/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8. | |
| Aplazada | Media (5.3) | 0.38% | — | Miniorange Oauth Single Sign ONAI | 6/2/2026 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14. This is due to missing capability checks and authentication verification on the OAuth redirect functionality accessible via the 'oauthredirect' option parameter. This… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Oauth Single Sign ON SSOAI | 4/10/2025 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token processing without verification or validation in the `get_resource_owner_from_id_token`… | |
| Aplazada | Media (4.3) | 0.17% | — | Miniorange Oauth Single Sign ONAI | 26/9/2025 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.26.12. This is due to using a predictable state parameter (base64 encoded app name) without any randomness in the OAuth flow. This makes it possible for unauthenticated… | |
| Modificada | Alta (8.8) | 0.96% | — | Miniorange Oauth Single Sign ON | 18/7/2023 | 17/6/2026 | Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3. | |
| Modificada | Media (6.5) | 0.33% | — | Miniorange Oauth Single Sign ON | 27/3/2023 | 17/6/2026 | The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack | |
| Modificada | Media (6.5) | 0.44% | — | Miniorange Oauth Single Sign ON | 27/3/2023 | 17/6/2026 | The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP),… | |
| Modificada | Media (5.3) | 1.2% | — | Miniorange Oauth Single Sign ON | 17/7/2022 | 17/6/2026 | The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address. |