Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.56% | — | Jenkins Openid | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to trick users into logging in to the attacker's account. | |
| Modificada | Media (6.1) | 0.66% | — | Jenkins Openid | 26/1/2023 | 17/6/2026 | Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins. | |
| Modificada | Crítica (9.8) | 1.1% | — | Jenkins Openid | 26/1/2023 | 17/6/2026 | Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login. | |
| Modificada | Alta (8.8) | 1.2% | — | Jenkins Openid Connect Authentication | 26/1/2023 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login. | |
| Modificada | Alta (7.5) | 0.89% | — | Jopenid Project Jopenid | 18/1/2023 | 16/6/2026 | A vulnerability, which was classified as problematic, was found in michaelliao jopenid. Affected is the function getAuthentication of the file JOpenId/src/org/expressme/openid/OpenIdManager.java. The manipulation leads to observable timing discrepancy. The complexity of an attack is rather high. The exploitability is… | |
| Modificada | Media (5.4) | 0.56% | — | Simplesamlphp-module-openidprovider | 17/1/2023 | 16/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in simplesamlphp simplesamlphp-module-openidprovider up to 0.8.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file templates/trust.tpl.php. The manipulation of the argument StateID leads to cross site… | |
| Modificada | Media (6.1) | 0.64% | — | Simplesamlphp-module-openid | 1/1/2023 | 16/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in SimpleSAMLphp simplesamlphp-module-openid. Affected is an unknown function of the file templates/consumer.php of the component OpenID Handler. The manipulation of the argument AuthState leads to cross site scripting. It is… | |
| Modificada | Media (6.1) | 0.91% | — | MOD Auth OpenidcDebian Linux | 14/12/2022 | 17/6/2026 | mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When providing a logout parameter to the redirect URI, the existing code in oidc_validate_redirect_url() does not properly check for URLs that… | |
| Modificada | Media (4.3) | 0.46% | — | Nextcloud Openid Connect User Backend | 25/11/2022 | 17/6/2026 | user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the OIDC client credentials and tokens are sent in plain text of HTTP without TLS. Any malicious actor with access to monitor user traffic may have been able to compromise account security. This issue… | |
| Modificada | Media (5.4) | 0.63% | — | Nextcloud Openid Connect User Backend | 25/11/2022 | 17/6/2026 | user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery urls which may lead to a stored cross site scripting attack vector. The impact is limited due to the restrictive CSP that is applied on this endpoint. Additionally this vulnerability has only been… | |
| Modificada | Alta (7.5) | 0.97% | — | Xwiki Openid Connect | 4/11/2022 | 17/6/2026 | XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Prior to version 1.29.1, even if a wiki has an OpenID provider configured through its xwiki.properties, it is possible to provide a third party provider its details through request parameters. One can then bypass the XWiki authentication… | |
| Modificada | Media (5.3) | 3.2% | 💥 PoC | Openidentityplatform Openam | 23/6/2022 | 17/6/2026 | The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack." | |
| Modificada | Media (6.1) | 0.74% | — | Auth0 Express Openid Connect | 31/3/2022 | 17/6/2026 | Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middleware, either directly or through the default `authRequired` option, are vulnerable to an Open Redirect when the middleware is applied to a catch all route. If all routes… | |
| Modificada | Alta (8.8) | 0.92% | — | Auth0 Express Openid Connect | 9/12/2021 | 17/6/2026 | Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in. This behavior opens up the application to various session fixation vulnerabilities. Versions… | |
| Modificada | Media (6.1) | 1.7% | — | MOD Auth OpenidcFedoraproject FedoraDebian Linux | 3/9/2021 | 17/6/2026 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO functionality of mod_auth_openidc was reported to be vulnerable to… | |
| Modificada | Media (6.1) | 1.5% | — | MOD Auth OpenidcFedoraproject Fedora | 26/7/2021 | 17/6/2026 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is an XSS vulnerability in when using `OIDCPreservePost On`. | |
| Modificada | Media (5.9) | 1.5% | — | MOD Auth OpenidcFedoraproject Fedora | 26/7/2021 | 17/6/2026 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, the AES GCM encryption in mod_auth_openidc uses a static IV and AAD. It is… | |
| Modificada | Media (6.1) | 2.4% | — | MOD Auth OpenidcFedoraproject Fedora | 22/7/2021 | 17/6/2026 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_url()` does not parse URLs the same way as most browsers do. As a… | |
| Modificada | Alta (7.5) | 2.7% | — | MOD Auth OpenidcNetapp Cloud BackupDebian Linux | 22/7/2021 | 17/6/2026 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc versions prior to 2.4.9 are configured to use an unencrypted Redis cache (`OIDCCacheEncrypt off`,… | |
| Modificada | Media (5.9) | 4.0% | 💥 Exploit | Openid | 21/5/2021 | 16/6/2026 | It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number Generator (CVE-2008-0166). In combination with the DNS Cache Poisoning issue (CVE-2008-1447) and the fact that almost all SSL/TLS implementations do not consult CRLs… | |
| Modificada | Alta (7.5) | 3.4% | — | MOD Auth OpenidcFedoraproject FedoraOracle Essbase | 20/5/2021 | 17/6/2026 | mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors. | |
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Daggerhartlab Openid Connect Generic Client | 6/5/2021 | 17/6/2026 | The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration. | |
| Modificada | Alta (8.8) | 1.0% | — | Hgiga Oaklouds Openid | 19/1/2021 | 17/6/2026 | HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data. | |
| Modificada | Crítica (9.8) | 1.2% | — | Hgiga Oaklouds Openid | 19/1/2021 | 17/6/2026 | HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data. | |
| Modificada | Media (6.8) | 0.83% | — | Python Openid Connect Project Python Openid Connect | 2/12/2020 | 17/6/2026 | Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The issues are: 1) The IdToken signature algorithm was not checked automatically, but only if the expected algorithm was passed… |