Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.4) | 0.39% | — | Vmware LdapAI | 9/6/2026 | 23/7/2026 | Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired with an empty or null password. Affected versions: Spring LDAP 2.4.0 through 2.4.4; 3.2.0 through 3.2.17; 3.3.0 through 3.3.7; 4.0.0 through 4.0.3. | |
| Analizada | Alta (8.8) | 0.26% | — | Apache Directory Ldap API | 1/6/2026 | 22/7/2026 | It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname. While the underlying code validates the certificate chain against a trusted authority, the absence of endpoint identification allows a valid certificate issued for an… | |
| Analizada | Media (6.6) | 0.43% | — | Jenkins Ldap | 27/5/2026 | 17/6/2026 | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation. | |
| Analizada | Media (6.6) | 0.37% | — | Jenkins Ldap | 27/5/2026 | 17/6/2026 | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals. | |
| Analizada | Alta (8.8) | 0.77% | — | Ldap-account-manager Ldap Account Manager | 18/3/2026 | 17/6/2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf,… | |
| Analizada | Alta (8.8) | 0.67% | — | Ldap-account-manager Ldap Account Manager | 18/3/2026 | 17/6/2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local file inclusion was detected in the PDF export that allows users to include local PHP files and this way execute code. In combination with GHSA-88hf-2cjm-m9g8… | |
| Aplazada | Alta (7.2) | 0.38% | — | Lemonldap NGAI | 16/1/2026 | 17/6/2026 | In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication. | |
| Aplazada | Media (4.6) | 0.15% | — | Openldap LmdbAI | 7/1/2026 | 17/6/2026 | OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds… | |
| Aplazada | Baja (2.9) | 0.30% | — | Opsre Go-ldap-adminAI | 3/12/2025 | 17/6/2026 | A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the file docs/docker-compose/docker-compose.yaml of the component JWT Handler. Executing manipulation of the argument secret key can lead to use of hard-coded cryptographic key . The attack can be… | |
| Analizada | Media (5.5) | 0.46% | — | Python-ldap | 10/10/2025 | 17/6/2026 | python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x00 incorrectly by emitting a backslash followed by a literal NUL byte instead of the RFC-4514 hex form \00. Any application that uses this helper to construct DNs from… | |
| Analizada | Media (5.5) | 0.32% | — | Python-ldap | 10/10/2025 | 17/6/2026 | python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the sanitization method `ldap.filter.escape_filter_chars` can be tricked to skip escaping of special characters when a crafted `list` or `dict` is supplied as the `assertion_value` parameter, and the… | |
| Aplazada | Alta (8) | 1.2% | — | Lemonldap NGAI | 17/9/2025 | 17/6/2026 | In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server. | |
| Aplazada | Media (4.6) | 0.18% | — | Ldap-account-manager Ldap Account ManagerAI | 16/9/2025 | 17/6/2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM before 9.3 allows stored cross-site scripting in the Profile section via the profile name field, which renders untrusted input as HTML and executes a supplied script (for example a script element). An authenticated user… | |
| Aplazada | Alta (7.1) | 0.13% | — | Aaron Axelsen Wpmu Ldap AuthenticationAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Aaron Axelsen WPMU Ldap Authentication wpmuldap allows Stored XSS.This issue affects WPMU Ldap Authentication: from n/a through <= 5.0.1. | |
| Aplazada | Media (5.4) | 0.22% | — | Ldap User ManagerAI | 7/2/2025 | 17/6/2026 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the LDAP User Manager <= ce92321, specifically in the /setup/index.php endpoint via the returnto parameter. This vulnerability arises due to improper sanitization of user-supplied input, allowing an attacker to inject malicious JavaScript. | |
| Analizada | Media (6.1) | 0.58% | — | Ibuildapp | 4/2/2025 | 17/6/2026 | The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Media (6.5) | 0.51% | — | Splunk Supporting Add-on FOR Active DirectoryAISplunk Sa-ldapsearchAI | 30/1/2025 | 17/6/2026 | In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Mendix LdapAI | 14/1/2025 | 17/6/2026 | A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerable to LDAP injection. This could allow an unauthenticated remote attacker to bypass username verification. | |
| Aplazada | Alta (7.1) | 0.39% | — | Frankkoenen Ldap Login Password AND Role ManagerAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in frankkoenen ldap_login_password_and_role_manager ldap-login-password-and-role-manager allows Stored XSS.This issue affects ldap_login_password_and_role_manager: from n/a through <= 1.0.12. | |
| Modificada | Crítica (9.8) | 0.58% | — | Buildapp Build APP Online | 7/1/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hakeemnala Build App Online build-app-online allows PHP Local File Inclusion.This issue affects Build App Online: from n/a through <= 1.0.23. | |
| Aplazada | Media (5) | 0.42% | — | PhpldapadminAI | 19/12/2024 | 17/6/2026 | phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LDAP directory into a Comma-Separated Value (CSV) file, but it does not neutralize special elements that could be interpreted as a command when the file is opened by a spreadsheet product. Thus, this… | |
| Aplazada | Baja (2.1) | 0.50% | — | PhpldapadminAI | 19/12/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However,… | |
| Aplazada | Media (6.5) | 0.70% | — | Ldap-account-manager Ldap Account ManagerAI | 17/12/2024 | 17/6/2026 | LDAP Account Manager (LAM) is a php webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In affected versions LAM does not properly sanitize configuration values, that are set via `mainmanage.php` and `confmain.php`. This allows setting arbitrary config values and thus… | |
| Aplazada | Baja (3.7) | 0.37% | — | Vmware LdapAI | 4/12/2024 | 17/6/2026 | A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from 3.1.0 through 3.1.7, from 3.2.0 through 3.2.7, AND all versions prior to 2.4.0. The usage of String.toLowerCase() and String.toUpperCase() has some… | |
| Modificada | Alta (8.8) | 0.18% | — | Buildapp Build APP Online | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in hakeemnala Build App Online build-app-online allows Cross Site Request Forgery.This issue affects Build App Online: from n/a through <= 1.0.23. |