Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.2)0.24%—Openidc CjoseAI9/9/202610/9/2026
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the attacker-supplied `encrypted_key` (JWE Encrypted…
AplazadaMedia (4.2)0.26%—Doorkeeper Openid ConnectAI25/8/20269/9/2026
Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this…
AplazadaAlta (7.5)0.72%—Apache Http ServerAIMOD Auth OpenidcAI21/8/202618/9/2026
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is…
AplazadaMedia (5.9)0.47%—Steeltoe Security Authentication CloudfoundrybaseAISteeltoe Security Authentication JwtbearerAISteeltoe Security Authentication OpenidconnectAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authentication.OpenIdConnect…
AnalizadaCrítica (9.3)8.4%—Openidentityplatform Openam7/4/202624/7/2026
Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter. This bypasses the WhitelistObjectInputStream mitigation that was…
AnalizadaMedia (4.2)0.21%—Bojanz Openid Connect / Oauth Client26/3/202617/6/2026
Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client allows Privilege Escalation.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.
AnalizadaMedia (6.5)0.42%—Bojanz Openid Connect / Oauth Client26/3/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authentication Bypass.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.
AnalizadaMedia (4.3)0.27%—Bojanz Openid Connect / Oauth Client26/3/202617/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forgery.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.
AplazadaMedia (6.4)0.23%—Daggerhartlab Openid Connect Generic ClientAI18/12/202517/6/2026
The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'openid_connect_generic_auth_url' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AnalizadaCrítica (9.1)0.64%—Jenkins Openid Connect Provider14/5/202517/6/2026
In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a trusted job,…
AplazadaAlta (8.2)0.57%—Apache MOD Auth OpenidcAIApache Http ServerAI6/4/202517/6/2026
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.16.11, a bug in a mod_auth_openidc results in disclosure of protected content to unauthenticated users. The conditions for…
AplazadaMedia (6.9)0.34%—Openid Connect CoreAI3/3/202517/6/2026
OpenID Connect Core through 1.0 errata set 2 allows audience injection in certain situations. When the private_key_jwt authentication mechanism is used, a malicious Authorization Server could trick a Client into writing attacker-controlled values into the audience, including token endpoints or issuer identifiers of…
AnalizadaAlta (8.8)0.55%—Jenkins Openid Connect Authentication22/1/202517/6/2026
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in…
AnalizadaMedia (6.1)0.25%—Miniorange Oauth & Openid Connect Single Sign-on9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows Cross-Site Scripting (XSS).This issue affects OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client): from 3.0.0 before 3.44.0,…
AnalizadaAlta (8.8)0.64%—Jenkins Openid Connect Authentication13/11/202417/6/2026
Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.
AplazadaMedia (5.4)0.23%—Duende Accesstokenmanagement OpenidconnectAI8/11/202417/6/2026
Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. HTTP Clients created by `AddUserAccessTokenHttpClient` may use a different user's access token after a token refresh occurs. This occurs because a refreshed token will be captured in pooled…
AnalizadaMedia (5.1)0.35%—F5 Nginx API Connectivity ManagerF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Openid Connect6/11/202417/6/2026
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session…
AnalizadaAlta (8.1)0.63%—Jenkins Openid Connect Authentication2/10/202417/6/2026
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.
AnalizadaAlta (8.1)0.63%—Jenkins Openid Connect Authentication2/10/202417/6/2026
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.
AplazadaAlta (7.1)0.40%—Diso Development Team OpenidAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DiSo Development Team OpenID allows Reflected XSS.This issue affects OpenID: from n/a through 3.6.1.
ModificadaAlta (7.5)1.3%—MOD Auth OpenidcDebian LinuxFedoraproject Fedora13/2/202417/6/2026
mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes the server vulnerable to a denial of…
AnalizadaMedia (6.1)0.60%—Jenkins Openid Connect Authentication13/12/202317/6/2026
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
ModificadaMedia (6.7)0.29%—Jenkins Openid13/12/202317/6/2026
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that account, likely gaining administrator access to…
ModificadaCrítica (9.8)1.3%—Openidentityplatform Openam20/7/202317/6/2026
Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of SAML responses received as part of the SAMLv1.x Single Sign-On process.…
AnalizadaAlta (7.5)1.3%—MOD Auth Openidc3/4/202317/6/2026
mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when `OIDCStripCookies` is set and a crafted cookie supplied, a NULL pointer dereference would occur, resulting in a…