Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
194 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 20/5/2026 | 21/8/2026 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the… | |
| Modificada | Media (5.4) | 0.28% | — | IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Verify Access | 25/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Modificada | Alta (7.5) | 0.38% | — | IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Verify Access | 25/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565. | |
| Modificada | Media (6.5) | 0.92% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/7/2024 | 17/6/2026 | A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service. | |
| Modificada | Media (5.5) | 0.31% | — | Redhat 389 Directory ServerRedhat Directory ServerFedoraproject FedoraRedhat Enterprise Linux+9 | 12/2/2024 | 17/6/2026 | A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. | |
| Modificada | Media (5.9) | 0.55% | — | IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Directory SuiteIBM Security Verify Directory | 14/10/2023 | 17/6/2026 | IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569. | |
| Modificada | Crítica (9.1) | 0.91% | — | IBM Security Directory ServerIBM Security Directory SuiteIBM Security Verify Directory | 14/10/2023 | 17/6/2026 | IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505. | |
| Modificada | Crítica (9.1) | 1.5% | — | IBM Security Directory Server | 8/9/2023 | 17/6/2026 | IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view or write to arbitrary files on the system. IBM X-Force ID: 228579. | |
| Modificada | Alta (7.8) | 0.33% | — | Nokia One-network Directory Server | 25/4/2023 | 17/6/2026 | Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation. | |
| Modificada | Media (5.5) | 0.19% | — | Redhat Directory ServerFedoraproject Fedora | 27/2/2023 | 17/6/2026 | A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed… | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Directory ServerRedhat Enterprise LinuxFedoraproject FedoraPort389 389-ds-base+1 | 14/10/2022 | 17/6/2026 | A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514. | |
| Modificada | Alta (7.5) | 1.5% | — | Redhat 389 Directory ServerRedhat Directory ServerRedhat Enterprise LinuxFedoraproject Fedora | 2/6/2022 | 17/6/2026 | An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database… | |
| Modificada | Media (6.5) | 1.5% | — | Redhat 389 Directory ServerFedoraproject FedoraRedhat Enterprise Linux | 23/3/2022 | 17/6/2026 | A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. | |
| Modificada | Media (6.5) | 1.2% | — | Redhat 389 Directory Server | 28/5/2021 | 17/6/2026 | When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash. | |
| Modificada | Media (5.3) | 1.5% | — | Redhat 389 Directory ServerRedhat Directory ServerRedhat Enterprise Linux | 26/3/2021 | 17/6/2026 | When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database. | |
| Modificada | Media (5.3) | 0.93% | — | IBM Security Directory Server | 29/10/2020 | 17/6/2026 | IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can… | |
| Modificada | Media (5.3) | 1.1% | — | IBM Security Directory Server | 29/10/2020 | 17/6/2026 | IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 165949. | |
| Analizada | Crítica (10) | 99% | ⚠ Explotación activa | Microsoft Windows Server 1903Microsoft Windows Server 1909Microsoft Windows Server 2004Microsoft Windows Server 2008+11 | 17/8/2020 | 17/6/2026 | An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the… | |
| Modificada | Media (5.3) | 0.98% | — | IBM Security Directory Server | 4/2/2020 | 17/6/2026 | IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. IBM X-Force ID: 166623. | |
| Modificada | Media (5.3) | 1.3% | — | IBM Security Directory Server | 4/2/2020 | 17/6/2026 | IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 165953. | |
| Modificada | Media (5.3) | 1.1% | — | IBM Security Directory Server | 4/2/2020 | 17/6/2026 | IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952. | |
| Modificada | Media (6.1) | 0.90% | — | IBM Security Directory Server | 4/2/2020 | 17/6/2026 | IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM… | |
| Modificada | Alta (7.2) | 1.3% | — | IBM Security Directory Server | 4/2/2020 | 17/6/2026 | IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 165814. | |
| Modificada | Alta (7.5) | 0.79% | — | IBM Security Directory Server | 4/2/2020 | 17/6/2026 | IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813. | |
| Modificada | Media (6.5) | 2.8% | — | SambaCanonical Ubuntu LinuxSynology Directory ServerSynology Router Manager+3 | 21/1/2020 | 17/6/2026 | There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer. |