Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.62%—Webauthn Provider FOR TWO FactorAI1/7/20261/7/2026
The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authentication response, allowing an attacker who already knows a user's password to bypass the two-factor authentication requirement by submitting a malformed request.
AplazadaAlta (7.5)0.42%—Yubico Webauthn-server-coreAIYubico Java-webauthn-serverAI14/5/202617/6/2026
Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.
AplazadaMedia (6.1)0.27%—Axton Wp-webauthnAI21/3/202617/6/2026
The WP-WebAuthn plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the `wwa_auth` AJAX endpoint in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on user supplied attributes logged by the plugin. This makes it possible for…
AnalizadaMedia (5.4)0.19%—Spomky-labs Webauthn-libSpomky-labs Webauthn-symfony-bundleSpomky-labs Webauthn Framwork10/3/202617/6/2026
web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. Prior to 5.2.4, when allowed_origins is configured, CheckAllowedOrigins reduces URL-like values to their host component and accepts on host match…
AnalizadaMedia (4.3)0.28%—Nextcloud Two-factor Webauthn5/12/202517/6/2026
Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing ownership check allowed an attack to take-away a 2FA webauthn device when correctly guessing a 80-128 character long random string of letters, numbers and symbols. The victim would then be prompted to…
AplazadaMedia (5.9)0.39%—Wikimedia Mediawiki Webauthn ExtensionAI17/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44.
AplazadaMedia (6.5)0.26%—Axton Wp-webauthnAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Axton WP-WebAuthn wp-webauthn allows Stored XSS.This issue affects WP-WebAuthn: from n/a through <= 1.3.1.
ModificadaMedia (5.4)0.41%—Axton Wp-webauthn28/9/202417/6/2026
The WP-WebAuthn plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wwa_login_form shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.39%—Spomky-labs Webauthn-libAI15/7/202417/6/2026
web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. The ProfileBasedRequestOptionsBuilder method returns allowedCredentials without any credentials if no username was found. When WebAuthn is used…
ModificadaMedia (5.3)0.52%—Webauthn4j Spring Security16/10/202317/6/2026
WebAuthn4J Spring Security provides Web Authentication specification support for Spring applications. Affected versions are subject to improper signature counter value handling. A flaw was found in webauthn4j-spring-security-core. When an authneticator returns an incremented signature counter value during…
ModificadaCrítica (9.8)1.8%—Spomky-labs Webauthn Framwork27/9/202117/6/2026
Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.
ModificadaAlta (7.5)1.6%—Stanford WebauthDebian Linux3/12/201916/6/2026
webauth before 4.6.1 has authentication credential disclosure
ModificadaMedia (4.3)0.86%—Stanford Webauth15/9/200916/6/2026
weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2)…