Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.21% | — | Two-factor AuthenticationAI | 27/5/2026 | 17/6/2026 | The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the ipv_save_changes function. This makes it possible for unauthenticated attackers to modify the… | |
| Analizada | Media (6.5) | 0.40% | — | Two-factor Authentication Project Two-factor Authentication | 8/7/2025 | 17/6/2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0. | |
| Analizada | Alta (8.1) | 0.39% | — | Two-factor Authentication Project Two-factor Authentication | 31/3/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0. | |
| Analizada | Crítica (9.8) | 0.46% | — | Two-factor Authentication Project Two-factor Authentication | 9/1/2025 | 17/6/2026 | Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0. | |
| Analizada | Crítica (9.8) | 0.56% | — | Two-factor Authentication Project Two-factor Authentication | 9/1/2025 | 17/6/2026 | Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0. | |
| Analizada | Media (5.3) | 0.24% | — | Youtag Two-factor Authentication | 31/8/2024 | 17/6/2026 | The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with… | |
| Modificada | Media (6.5) | 0.59% | — | Born05 Two-factor Authentication | 6/6/2024 | 17/6/2026 | The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. | |
| Modificada | Alta (8.1) | 0.83% | — | Born05 Two-factor Authentication | 6/6/2024 | 17/6/2026 | The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP. | |
| Modificada | Media (5.4) | 0.70% | — | Django Two-factor Authentication Project Django Two-factor Authentication | 10/7/2020 | 17/6/2026 | Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authentication code. This means… | |
| Modificada | Media (6.1) | 0.99% | — | Simbahosting Two-factor-authentication | 28/8/2019 | 17/6/2026 | The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area. | |
| Modificada | Alta (8.8) | 1.4% | — | Simbahosting Two-factor-authentication | 19/12/2018 | 17/6/2026 | Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due to missing nonce validation. | |
| Modificada | Media (6.1) | 0.95% | — | Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+4 | 20/12/2017 | 17/6/2026 | The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,… |