Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service FOR AD FS Agent2/3/201817/6/2026
SafeNet Authentication Service for AD FS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.8)0.41%—Gemalto Safenet Authentication Service FOR Outlook WEB APP Agent2/3/201817/6/2026
SafeNet Authentication Service for Outlook Web App Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service Remote WEB Workplace Agent2/3/201817/6/2026
SafeNet Authentication Service Remote Web Workplace Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service Tokenvalidator Proxy Agent2/3/201817/6/2026
SafeNet Authentication Service TokenValidator Proxy Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service IIS Agent2/3/201817/6/2026
SafeNet Authentication Service IIS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.8)0.38%—Gemalto Safenet Authentication Service END User Software Tools FOR Windows2/3/201817/6/2026
SafeNet Authentication Service End User Software Tools for Windows uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (8.8)1.9%—Apache Sling Authentication Service18/12/201717/6/2026
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials.
ModificadaAlta (7.5)2.8%—Apereo Central Authentication Service10/2/201517/6/2026
Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication.
ModificadaAlta (7.8)3.8%—Safenet-inc Safenet Authentication Service Outlook WEB Access Agent16/12/201417/6/2026
Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard) before 1.03.30109 allows remote attackers to read arbitrary files via a .. (dot dot) in the GetFile parameter to owa/owa.
ModificadaMedia (5)16%—Microsoft Internet Authentication Service Helper COM Component29/9/200816/6/2026
A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll allows remote attackers to cause a denial of service (browser crash) via a large integer value in the first argument to the PutProperty method. NOTE: this issue was disclosed by an unreliable…
ModificadaMedia (4.9)0.34%—Novell Modular Authentication Service12/6/200716/6/2026
NMASINST in Novell Modular Authentication Service (NMAS) 3.1.2 and earlier on NetWare logs its invoking command line to NMASINST.LOG, which might allow local users to obtain the admin username and password by reading this file.