Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 300 respecto a la semana anterior
Críticas / altas1352▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.27% | — | AuthorizerAI | 1/10/2026 | 1/10/2026 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | Steeltoe.security.authorization.certificateAI | 17/9/2026 | 30/9/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the… | |
| Aplazada | Media (5.4) | 0.24% | — | Publishpress AuthorsAI | 15/9/2026 | 15/9/2026 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up to, and including, 4.15.0 due to insufficient input sanitization and output… | |
| Aplazada | Crítica (9.3) | 0.46% | — | AuthorizerAI | 11/9/2026 | 30/9/2026 | Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server appends `access_token`, `id_token`, and… | |
| Aplazada | Alta (8.8) | 0.67% | — | CmsimpleAICmsimple CoauthorsAI | 8/9/2026 | 9/9/2026 | A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing crafted external or uploaded text content through the affected content import feature. | |
| Aplazada | Crítica (9.8) | 0.48% | — | AuthorizerAI | 2/9/2026 | 2/9/2026 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | |
| Pendiente de análisis | Media (6.5) | 0.32% | — | Apache HttpdAIDogtag Certificate AuthorityAIRedhat Identity ManagementAI | 1/9/2026 | 1/9/2026 | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion… | |
| Analizada | Alta (8.2) | 0.32% | — | Broadcom Spring Authorization Server | 27/8/2026 | 31/8/2026 | Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page… | |
| Analizada | Media (6.1) | 0.24% | — | Broadcom Spring Authorization Server | 27/8/2026 | 1/9/2026 | In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an… | |
| Aplazada | Alta (8.4) | 0.19% | — | Estonian Information System Authority Digidoc4AI | 20/8/2026 | 1/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client. This issue affects DigiDoc4: from 4.0.0 before 4.11.0. | |
| Aplazada | Alta (8.8) | 0.47% | — | Cedar Policy Authorization FOR ExpressjsAIExpressAI | 13/8/2026 | 9/9/2026 | @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. Versions prior to 0.3.0 have an issue where, under certain… | |
| Aplazada | Media (4.4) | 0.12% | — | Estonian Information System Authority LibdigidocppAIEstonian Information System Authority Digidoc4AIEstonian Information System Authority Digidoc ON AndroidAIEstonian Information System Authority Digidoc ON IOSAI | 10/8/2026 | 1/9/2026 | Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before… | |
| Aplazada | Media (5.5) | 0.67% | — | Lmammino Oidc-authorizerAI | 9/8/2026 | 12/8/2026 | A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda Authorizer. The manipulation results in sensitive information in log files. The attack can be executed remotely. `src/handler.rs` logs raw Authorization header values… | |
| Aplazada | Media (5.5) | 0.64% | — | Lmammino Oidc-authorizerAI | 9/8/2026 | 12/8/2026 | A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_header of the file src/parse_token_from_header.rs of the component Authorization Header Parsing. The manipulation of the argument authorization_token leads to denial of service. Remote exploitation of the… | |
| Aplazada | Media (6.5) | 0.41% | — | Afthemes WP Post AuthorAI | 5/8/2026 | 12/8/2026 | The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the 'wpma_metabox_authors_list' parameter in all versions up to, and including, 3.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Aplazada | Media (6.5) | 0.27% | — | Authora Easy Login With Mobile NumberAI | 1/8/2026 | 26/8/2026 | The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know… | |
| Analizada | Alta (7.5) | 0.74% | — | Linuxfoundation Sigstore Timestamp Authority | 17/7/2026 | 30/7/2026 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote… | |
| Analizada | Crítica (9.6) | 0.48% | — | Broadcom Spring Authorization Server | 16/7/2026 | 4/9/2026 | Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10. | |
| Aplazada | Media (6.5) | 0.22% | — | Netrr Author BOX WP LensAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Netrr Author Box WP Lens author-box-for-divi allows Stored XSS.This issue affects Author Box WP Lens: from n/a through <= 2.1.5. | |
| Aplazada | Alta (8.5) | 0.36% | — | Afthemes WP Post AuthorAI | 26/6/2026 | 26/6/2026 | Contributor SQL Injection in WP Post Author <= 3.9.1 versions. | |
| Analizada | Media (6.1) | 0.37% | — | Aqara Cloud Oauth Authorization Endpoint | 12/6/2026 | 9/7/2026 | The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe Equivalence in Input" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N… | |
| Analizada | Media (6.1) | 0.25% | — | Broadcom Spring Authorization ServerVmware Spring Security | 10/6/2026 | 23/7/2026 | Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability. Affected… | |
| Aplazada | Media (4.3) | 0.41% | — | ThorvgAI | 1/6/2026 | 22/7/2026 | Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes untrusted SVG data to Picture::load() to crash the process with a 6-byte payload. This issue has been patched in version 1.0.5. | |
| Analizada | Media (6.5) | 0.77% | — | Powerdns Authoritative | 21/5/2026 | 23/7/2026 | Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail | |
| Analizada | Alta (7.5) | 0.58% | — | Powerdns Authoritative | 21/5/2026 | 23/7/2026 | Concurrency and locking defects in GSS-TSIG |