Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service FOR AD FS Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service for AD FS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.8) | 0.41% | — | Gemalto Safenet Authentication Service FOR Outlook WEB APP Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service for Outlook Web App Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service Remote WEB Workplace Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service Remote Web Workplace Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service Tokenvalidator Proxy Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service TokenValidator Proxy Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service IIS Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service IIS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.8) | 0.38% | — | Gemalto Safenet Authentication Service END User Software Tools FOR Windows | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service End User Software Tools for Windows uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (8.8) | 1.9% | — | Apache Sling Authentication Service | 18/12/2017 | 17/6/2026 | A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials. | |
| Modificada | Alta (7.5) | 2.8% | — | Apereo Central Authentication Service | 10/2/2015 | 17/6/2026 | Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication. | |
| Modificada | Alta (7.8) | 3.8% | — | Safenet-inc Safenet Authentication Service Outlook WEB Access Agent | 16/12/2014 | 17/6/2026 | Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard) before 1.03.30109 allows remote attackers to read arbitrary files via a .. (dot dot) in the GetFile parameter to owa/owa. | |
| Modificada | Media (5) | 16% | — | Microsoft Internet Authentication Service Helper COM Component | 29/9/2008 | 16/6/2026 | A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll allows remote attackers to cause a denial of service (browser crash) via a large integer value in the first argument to the PutProperty method. NOTE: this issue was disclosed by an unreliable… | |
| Modificada | Media (4.9) | 0.34% | — | Novell Modular Authentication Service | 12/6/2007 | 16/6/2026 | NMASINST in Novell Modular Authentication Service (NMAS) 3.1.2 and earlier on NetWare logs its invoking command line to NMASINST.LOG, which might allow local users to obtain the admin username and password by reading this file. |