Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.43% | — | Russellhaering Gosaml2AICasbin CasdoorAI | 28/5/2026 | 17/6/2026 | Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning that time bounds are computed by the… | |
| Analizada | Media (6.1) | 0.27% | — | Simplesamlphp-module-casserver | 18/5/2026 | 30/9/2026 | SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redirect to. casserver treats that url as trusted, and either (depending on configuration) redirects the browser there, or… | |
| Analizada | Crítica (9.1) | 0.80% | — | Microsoft Confluence Saml SSOMicrosoft Jira Saml SSO | 12/5/2026 | 17/6/2026 | Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.1) | 0.25% | — | Miniorange Saml SSO - Service Provider | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - Service Provider allows Cross-Site Scripting (XSS).This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.3. | |
| Modificada | Media (6.3) | 0.45% | — | Arekinath EsamlDropbox EsamlHandnot2 EsamlJump-app Esaml | 23/3/2026 | 24/7/2026 | XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messages. esaml parses attacker-controlled SAML messages using xmerl_scan:string/2… | |
| Analizada | Alta (8.2) | 0.17% | — | Simplesamlphp Xml-security | 16/3/2026 | 17/6/2026 | xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover the GHASH key,… | |
| Analizada | Crítica (9.3) | 0.23% | — | Onelogin Ruby-saml | 9/12/2025 | 17/6/2026 | The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for document transformation, which allows an attacker to execute a Signature Wrapping attack. When… | |
| Analizada | Crítica (9.3) | 0.39% | — | Onelogin Ruby-saml | 9/12/2025 | 17/6/2026 | The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for CVE-2025-25292. ReXML and Nokogiri parse XML differently, generating entirely different document structures from… | |
| Analizada | Alta (7.5) | 0.47% | — | Jenkins Saml | 29/10/2025 | 17/6/2026 | Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user. | |
| Aplazada | Media (6.5) | 0.40% | — | Cloud Saml SSOAI | 6/9/2025 | 17/6/2026 | The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on the delete_config action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. This makes it possible for unauthenticated attackers to delete any configured IdP,… | |
| Aplazada | Alta (8.2) | 0.28% | — | Cloud Saml SSOAI | 6/9/2025 | 17/6/2026 | The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'set_organization_settings' action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. The handler reads client-supplied POST parameters for organization… | |
| Aplazada | Alta (8.7) | 0.24% | — | Mendix SamlAIMendix 10.12AIMendix 10.21AIMendix 9.24AI | 14/8/2025 | 17/6/2026 | A vulnerability has been identified in Mendix SAML (Mendix 10.12 compatible) (All versions < V4.0.3), Mendix SAML (Mendix 10.21 compatible) (All versions < V4.1.2), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.21). Affected versions of the module insufficiently enforce signature validation and binding… | |
| Aplazada | Alta (7.5) | 0.61% | — | Cloud Infrastructure Services Cloud Saml SSO Single Sign ONAI | 14/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cloud Infrastructure Services Cloud SAML SSO - Single Sign On Login cloud-sso-single-sign-on allows PHP Local File Inclusion.This issue affects Cloud SAML SSO - Single Sign On Login: from n/a… | |
| Aplazada | Crítica (9.6) | 0.40% | — | Zscaler Saml AuthenticationAI | 5/8/2025 | 17/6/2026 | An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse. | |
| Aplazada | Media (6.9) | 0.40% | — | Onelogin Ruby-samlAI | 30/7/2025 | 17/6/2026 | The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to… | |
| Aplazada | Crítica (10) | 0.36% | — | Node-samlAI | 28/7/2025 | 17/6/2026 | A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an attacker to modify authentication details within a valid SAML… | |
| Aplazada | Crítica (9.3) | 0.55% | — | Node-samlAI | 24/7/2025 | 17/6/2026 | Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an attacker to modify authentication details… | |
| Analizada | Media (5.3) | 0.47% | — | Assamlook CMS | 2/6/2025 | 17/6/2026 | A vulnerability has been found in AssamLook CMS 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /view_tender.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.3) | 0.45% | — | Assamlook CMS | 2/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in AssamLook CMS 1.0. Affected is an unknown function of the file /department-profile.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (5.3) | 0.50% | — | Assamlook CMS | 2/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in AssamLook CMS 1.0. This issue affects some unknown processing of the file /product.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Crítica (9.9) | 0.47% | — | Samlify Project Samlify | 19/5/2025 | 17/6/2026 | samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to version 2.10.0, allowing an attacker to forge a SAML Response to authenticate as any user. An attacker would need a signed XML document by the identity provider. Version 2.10.0 fixes the issue. | |
| Aplazada | Alta (8.6) | 0.37% | — | Auth0 Passport-wsfed-saml2AI | 6/5/2025 | 17/6/2026 | passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication by tampering with a valid SAML response. This can be done by adding attributes to… | |
| Aplazada | Crítica (9.3) | 0.42% | — | Auth0 Passport-wsfed-saml2AI | 6/5/2025 | 17/6/2026 | passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication by crafting a SAMLResponse. This can be done by using a valid SAML object that… | |
| Aplazada | Media (4) | 0.24% | — | Opensaml C++AI | 28/3/2025 | 17/6/2026 | The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures). | |
| Modificada | Alta (7.7) | 1.5% | — | Omniauth SamlOnelogin Ruby-saml | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to… |