Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.21%—Two-factor AuthenticationAI27/5/202617/6/2026
The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the ipv_save_changes function. This makes it possible for unauthenticated attackers to modify the…
AnalizadaMedia (6.5)0.40%—Two-factor Authentication Project Two-factor Authentication8/7/202517/6/2026
Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0.
AnalizadaAlta (8.1)0.39%—Two-factor Authentication Project Two-factor Authentication31/3/202517/6/2026
Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0.
AnalizadaCrítica (9.8)0.46%—Two-factor Authentication Project Two-factor Authentication9/1/202517/6/2026
Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.
AnalizadaCrítica (9.8)0.56%—Two-factor Authentication Project Two-factor Authentication9/1/202517/6/2026
Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0.
AnalizadaMedia (5.3)0.24%—Youtag Two-factor Authentication31/8/202417/6/2026
The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with…
ModificadaMedia (6.5)0.59%—Born05 Two-factor Authentication6/6/202417/6/2026
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.
ModificadaAlta (8.1)0.83%—Born05 Two-factor Authentication6/6/202417/6/2026
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
ModificadaMedia (5.4)0.70%—Django Two-factor Authentication Project Django Two-factor Authentication10/7/202017/6/2026
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authentication code. This means…
ModificadaMedia (6.1)0.99%—Simbahosting Two-factor-authentication28/8/201917/6/2026
The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area.
ModificadaAlta (8.8)1.4%—Simbahosting Two-factor-authentication19/12/201817/6/2026
Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due to missing nonce validation.
ModificadaMedia (6.1)0.95%—Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+420/12/201717/6/2026
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,…