Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 0.43% | — | Dani-garcia VaultwardenAI | 22/9/2026 | 24/9/2026 | Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization ciphers. Attackers with revoked or pending membership can exploit missing status… | |
| Aplazada | Alta (7.7) | 0.45% | — | Dani-garcia VaultwardenAI | 15/7/2026 | 15/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to an existing local account, allowing an attacker-controlled IdP identity… | |
| Aplazada | Media (5.8) | 0.40% | — | Dani-garcia VaultwardenAI | 15/7/2026 | 15/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that missed decimal, hexadecimal, and octal IP representations, allowing SSRF through the icon-fetching HTTP… | |
| Aplazada | Media (6.9) | 0.66% | — | Dani-garcia VaultwardenAI | 15/7/2026 | 15/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation JWT to be obtained with only the… | |
| Aplazada | Alta (8.3) | 0.25% | — | Dani-garcia VaultwardenAI | 15/7/2026 | 15/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left SsoAuth records intact after failed token… | |
| Analizada | Crítica (9.8) | 0.49% | — | Dani-garcia Vaultwarden | 11/5/2026 | 17/6/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled. If email 2fa is enabled, the unprotected 2fa-function send_email_login (email.rs, api endpoint… | |
| Analizada | Alta (8.1) | 0.40% | — | Dani-garcia Vaultwarden | 11/5/2026 | 17/6/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flow uses a two-step process: accepting an invite transitions membership from Invited to Accepted, and a separate… | |
| Analizada | Alta (8.7) | 0.40% | — | Dani-garcia Vaultwarden | 11/5/2026 | 17/6/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as groups.groups_uuid, or a collections_groups.collections_uuid entry belongs to the same organization as… | |
| Analizada | Alta (8.1) | 0.31% | — | Dani-garcia Vaultwarden | 11/5/2026 | 17/6/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (password change, KDF change, key rotation, email change, org admin password reset, emergency access takeover). This allows… | |
| Analizada | Media (5.3) | 0.28% | — | Dani-garcia Vaultwarden | 5/5/2026 | 24/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the has_full_access() authorization check that exists on the sibling get_org_collections endpoint. This allows any… | |
| Analizada | Media (5.3) | 0.19% | — | Dani-garcia Vaultwarden | 5/5/2026 | 25/7/2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flow in `validate_webauthn_login()` updates persistent credential metadata (1backup_eligible1 and 1backup_state flags1) based on unverified `authenticatorData` before signature validation is… | |
| Analizada | Media (5.4) | 0.24% | — | Dani-garcia Vaultwarden | 4/3/2026 | 17/6/2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though the standard retrieval API correctly denies access to that cipher,… | |
| Analizada | Alta (8.3) | 0.39% | — | Dani-garcia Vaultwarden | 4/3/2026 | 17/6/2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as they have access to the collection. This issue has been patched in… | |
| Analizada | Alta (8.3) | 0.39% | — | Dani-garcia Vaultwarden | 4/3/2026 | 17/6/2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Manager. This issue has been patched in version 1.35.4. | |
| Analizada | Media (6) | 0.25% | — | Dani-garcia Vaultwarden | 4/3/2026 | 17/6/2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated access to a user’s account can exploit this bypass to perform protected… | |
| Analizada | Media (6.5) | 0.38% | — | Dani-garcia Vaultwarden | 11/2/2026 | 17/6/2026 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.3, a regular organization member can retrieve all ciphers within an organization, regardless of collection permissions. The endpoint /ciphers/organization-details is accessible to any organization… | |
| Analizada | Alta (7.5) | 0.68% | — | Dani-garcia Vaultwarden | 27/1/2025 | 17/6/2026 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can be a part of the organization as an unprivileged user) and be the owner/admin of… | |
| Analizada | Alta (7.2) | 1.0% | — | Dani-garcia Vaultwarden | 27/1/2025 | 17/6/2026 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code in the system. The attacker could then change some settings to use sendmail as mail agent but adjust the settings in… | |
| Analizada | Media (5.4) | 0.38% | — | Dani-garcia Vaultwarden | 9/1/2025 | 17/6/2026 | Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs. | |
| Analizada | Crítica (9.8) | 0.60% | — | Dani-garcia Vaultwarden | 9/1/2025 | 17/6/2026 | An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request. | |
| Analizada | Crítica (9.6) | 0.82% | — | Dani-garcia Vaultwarden | 9/1/2025 | 17/6/2026 | An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message. | |
| Analizada | Alta (7.5) | 0.34% | — | Dani-garcia Vaultwarden | 20/12/2024 | 17/6/2026 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. The attacker has a user account in the server. 2. The attacker's account has admin or… | |
| Analizada | Media (5.4) | 0.46% | — | Dani-garcia Vaultwarden | 13/9/2024 | 17/6/2026 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This potentially allows an authenticated attacker to inject malicious code into the dashboard, which is then… | |
| Analizada | Media (6.5) | 0.57% | — | Dani-garcia Vaultwarden | 13/9/2024 | 17/6/2026 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs. Consequently, the departing member, whose access should be revoked, retains a copy of the… | |
| Analizada | Alta (8.8) | 13% | — | Dani-garcia Vaultwarden | 13/9/2024 | 17/6/2026 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency access to escalate their privileges by… |