Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

869 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.3%—IBM Security Directory Server4/2/202017/6/2026
IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 165953.
ModificadaMedia (5.3)1.1%—IBM Security Directory Server4/2/202017/6/2026
IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952.
ModificadaMedia (6.1)0.90%—IBM Security Directory Server4/2/202017/6/2026
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM…
ModificadaAlta (7.2)1.3%—IBM Security Directory Server4/2/202017/6/2026
IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 165814.
ModificadaAlta (7.5)0.79%—IBM Security Directory Server4/2/202017/6/2026
IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813.
ModificadaMedia (6.5)1.0%—Cmsjunkie J-businessdirectory3/2/202017/6/2026
The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be entered by any user. If it doesn't contain rel="noopener" (or similar attributes such as noreferrer), the tabnabbing may occur. To reproduce the bug, create a business…
ModificadaMedia (6.5)2.8%—SambaCanonical Ubuntu LinuxSynology Directory ServerSynology Router Manager+321/1/202017/6/2026
There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.
ModificadaMedia (6.5)3.2%—SambaFedoraproject FedoraRedhat StorageRedhat Enterprise Linux+621/1/202017/6/2026
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In…
ModificadaBaja (3.3)0.26%—Hp-ux Directory ServerRedhat Directory ServerFedoraproject 389 Directory ServerRedhat Directory Server9/1/202016/6/2026
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by…
ModificadaMedia (4.6)0.40%—Fedoraproject 389 Directory Server25/11/201917/6/2026
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain…
ModificadaMedia (6.5)1.3%—Fedoraproject 389 Directory ServerRedhat Enterprise LinuxDebian Linux8/11/201917/6/2026
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
ModificadaAlta (7.5)1.3%—Redhat Directory ServerRedhat 389 Directory Server5/11/201916/6/2026
The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.
ModificadaMedia (5.3)1.3%—IBM Security Directory Server2/10/201917/6/2026
IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 165951.
ModificadaMedia (6.1)0.90%—IBM Security Directory Server2/10/201917/6/2026
IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 165815.
ModificadaAlta (7.1)1.2%—IBM Security Directory Server2/10/201917/6/2026
IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system. IBM X-Force ID: 165812.
ModificadaAlta (8.2)1.3%—IBM Security Directory Server2/10/201917/6/2026
IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would…
ModificadaAlta (7.5)2.2%—IBM Security Directory Server2/10/201917/6/2026
IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 165178.
ModificadaAlta (8.8)3.8%—Microsoft Active Directory Authentication LibraryMicrosoft Nuget14/8/201917/6/2026
An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in the way the library caches tokens. This vulnerability allows an authenticated attacker to perform actions in context of another user. The authenticated attacker can exploit this vulneraiblity by…
ModificadaAlta (7.5)1.4%—Fedoraproject 389 Directory ServerRedhat Enterprise Linux Server EUS2/8/201917/6/2026
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
ModificadaMedia (5.3)1.8%—Microsoft Azure Active Directory Connect16/5/201917/6/2026
An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two PowerShell cmdlets in context of a privileged account, and perform privileged actions.To exploit this, an attacker would need to authenticate to the Azure AD Connect…
ModificadaAlta (7.5)92%💥 ExploitApache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+331/5/201917/6/2026
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version…
ModificadaMedia (5.3)5.9%—Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+2222/4/201917/6/2026
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path.…
ModificadaMedia (5.3)4.1%—Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+2122/4/201917/6/2026
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in…
ModificadaAlta (7.5)8.2%—Fedoraproject 389 Directory ServerDebian LinuxRedhat Enterprise Linux17/4/201917/6/2026
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang…
ModificadaMedia (6.1)0.55%—SambaFedoraproject FedoraSynology Directory ServerSynology Router Manager+39/4/201917/6/2026
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded…
Orbitaley — Vulnerabilidades