Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.18% | — | Mskcc Oauth2 Client | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal OAuth2 Client allows Cross Site Request Forgery.This issue affects OAuth2 Client: from 0.0.0 before 4.1.3. | |
| Modificada | Media (6.1) | 0.56% | — | Owncloud Oauth2 | 21/11/2023 | 17/6/2026 | An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently allows an attacker to redirect callbacks to a Top Level Domain controlled by the attacker. | |
| Modificada | Media (5.9) | 0.55% | — | Networknt Light-oauth2 | 25/10/2023 | 17/6/2026 | light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token. | |
| Modificada | Alta (7.5) | 0.95% | — | Thephpleague Oauth2-server | 6/7/2023 | 17/6/2026 | league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2 and prior to version 8.5.3, servers that passed their keys to the CryptKey constructor as as string instead of a file path will have had that key included in a LogicException message if they did not… | |
| Modificada | Alta (8.8) | 0.70% | — | Fastify Oauth2 | 4/7/2023 | 17/6/2026 | All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all requests for all users. The purpose of the Oauth2 state parameter is to prevent Cross-Site-Request-Forgery attacks. As such, it should be unique per user and should be connected to the user's session in… | |
| Modificada | Crítica (9.8) | 14% | — | Logrocket-oauth2-example Project Logrocket-oauth2-example | 14/12/2022 | 17/6/2026 | logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter. | |
| Modificada | Alta (7.2) | 0.97% | — | Oauth2-server Project Oauth2-server | 29/8/2022 | 17/6/2026 | In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern ("[a-zA-Z][a-zA-Z0-9+.-]+:") before making a redirection. This allows a malicious client to pass an XSS payload through the… | |
| Modificada | Crítica (9.8) | 1.1% | — | Codexshaper WP Oauth2 Server | 22/7/2022 | 17/6/2026 | Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress. | |
| Modificada | Media (6.1) | 0.56% | — | Scratchoauth2 Project Scratchoauth2 | 15/2/2022 | 17/6/2026 | A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request. | |
| Modificada | Crítica (10) | 1.1% | — | Scratchoauth2 Project Scratchoauth2 | 15/2/2022 | 17/6/2026 | An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components that rely on ScratchOAuth2. | |
| Modificada | Media (6.5) | 0.64% | — | Scratchoauth2 Project Scratchoauth2 | 15/2/2022 | 17/6/2026 | An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps. | |
| Modificada | Media (5.3) | 1.3% | — | Passportjs Passport-oauth2 | 27/9/2021 | 17/6/2026 | The passport-oauth2 package before 1.6.1 for Node.js mishandles the error condition of failure to obtain an access token. This is exploitable in certain use cases where an OAuth identity provider uses an HTTP 200 status code for authentication-failure error reports, and an application grants authorization upon simply… | |
| Modificada | Media (6.8) | 0.81% | — | Scratchoauth2 Project Scratchoauth2 | 13/4/2021 | 17/6/2026 | ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable by a user can be read and modified by a third party. 1. Scratch user visits 3rd party site. 2. 3rd party site asks user for Scratch username. 3. 3rd party site pretends to be user and gets login code… | |
| Modificada | Media (5.5) | 1.1% | — | Oauth2 Proxy Project Oauth2 Proxy | 26/3/2021 | 17/6/2026 | OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group-based authorization in the GitLab provider stopped working in the v7.0.0 release. Regardless of the flag settings, authorization wasn't restricted. Additionally, any… | |
| Modificada | Media (6.1) | 1.6% | — | Oauth2 Proxy Project Oauth2 Proxy | 2/2/2021 | 17/6/2026 | OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain or group. In OAuth2 Proxy before version 7.0.0, for users that use the whitelist domain feature, a domain that ended in a similar way to… | |
| Modificada | Alta (7.5) | 2.2% | — | Oauth2-server Project Oauth2-server | 4/10/2020 | 17/6/2026 | oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As RFC7636 is an extension, I think the claim in the Readme of "RFC 6749 compliant" is valid and not misleading and I also… | |
| Modificada | Media (5.4) | 0.90% | — | Oauth2 Proxy Project Oauth2 Proxy | 29/6/2020 | 17/6/2026 | In OAuth2 Proxy from version 5.1.1 and less than version 6.0.0, users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is expected to be the original URL that the user was trying to access. This redirect URL is checked within the proxy and… | |
| Modificada | Media (6.1) | 0.79% | — | Oauth2 Proxy Project Oauth2 Proxy | 7/5/2020 | 17/6/2026 | In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is expected to be the original URL that the user was trying to access. This redirect URL is checked within the proxy… | |
| Modificada | Crítica (9.8) | 2.4% | — | Omniauth-weibo-oauth2 Project Omniauth-weibo-oauth2 | 7/2/2020 | 17/6/2026 | The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected. | |
| Modificada | Media (6.1) | 1.3% | — | Oauth2 Proxy Project Oauth2 Proxy | 30/1/2020 | 17/6/2026 | OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0. | |
| Modificada | Alta (8.8) | 1.2% | — | Schine.games Mw-oauth2client | 19/8/2019 | 17/6/2026 | In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function. | |
| Modificada | Media (6.1) | 0.91% | — | Oauth2orize-fprm Project Oauth2orize-fprm | 17/6/2018 | 17/6/2026 | index.js in oauth2orize-fprm before 0.2.1 has XSS via a crafted URL. | |
| Modificada | Media (6.1) | 1.00% | — | Oauth2 Proxy Project Oauth2 Proxy | 17/7/2017 | 17/6/2026 | The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819 | |
| Modificada | Alta (8.8) | 0.74% | — | Oauth2 Proxy Project Oauth2 Proxy | 17/7/2017 | 17/6/2026 | CSRF in Bitly oauth2_proxy 2.1 during authentication flow | |
| Modificada | Media (5.8) | 2.5% | — | Urbanairship Python-oauth2 | 20/5/2014 | 16/6/2026 | The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack. |