Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.31% | — | Lemonldap NGAI | 18/11/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the "Upgrade session" plugin has been enabled by an admin | |
| Aplazada | Alta (8.8) | 0.49% | — | Lemonldap NGAI | 18/11/2024 | 17/6/2026 | An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value. | |
| Aplazada | Crítica (9.1) | 0.41% | — | Lemonldap NGAI | 10/11/2024 | 17/6/2026 | An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e., it does not verify access token validity. An attacker can use a expired access token from an OIDC client to access the OAuth2 handler The earliest affected version is 2.0.4. | |
| Modificada | Media (6.1) | 0.33% | — | Lemonldap-ng Lemonldap\ | 9/10/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters. | |
| Aplazada | Crítica (9.1) | 0.52% | — | Lemonldap NGAI | 9/10/2024 | 17/6/2026 | Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret). | |
| Analizada | Media (6.1) | 0.43% | — | Objectiv Simple Ldap Login | 28/9/2024 | 17/6/2026 | The Simple LDAP Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Aplazada | Media (5.3) | 0.43% | — | Mhuertos PhpldapadminAI | 11/7/2024 | 17/6/2026 | A vulnerability classified as critical was found in mhuertos phpLDAPadmin up to 665dbc2690ebeb5392d38f1fece0a654225a0b38. Affected by this vulnerability is the function makeHttpRequest of the file htdocs/js/ajax_functions.js. The manipulation leads to http request smuggling. The attack can be launched remotely. This… | |
| Aplazada | Media (6.3) | 0.42% | — | Openvpn Auth LdapAI | 27/6/2024 | 17/6/2026 | Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-auth-ldap (aka the Three Rings Auth-LDAP plugin for OpenVPN) 2.0.4 allows attackers with a valid LDAP username and who can control the challenge/response password field to pass a string with more than 14 colons into this field and cause a… | |
| Modificada | Crítica (9.8) | 0.62% | — | Buildapp Build APP Online | 11/6/2024 | 17/6/2026 | The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code. | |
| Analizada | Alta (8.8) | 0.48% | — | Buildapp Build APP Online | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19. | |
| Modificada | Crítica (9.8) | 0.70% | — | Buildapp Build APP Online | 25/4/2024 | 17/6/2026 | Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19. | |
| Analizada | Media (6.6) | 18% | — | Ldap-account-manager Ldap Account Manager | 18/3/2024 | 17/6/2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration allows to specify arbitrary paths for log files. Prior to version 8.7, an attacker could exploit this by creating a PHP file and cause LAM to log some PHP code to this file. When the file is then… | |
| Analizada | Media (6.1) | 0.56% | — | Manuelaldape Parents & Student Portal | 29/2/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIMS Student Information Systems v.3053 allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Media (6.7) | 0.21% | — | Okta Ldap Agent | 8/11/2023 | 17/6/2026 | The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution. | |
| Modificada | Alta (7.5) | 26% | 💥 Exploit | Miniorange Active Directory Integration / Ldap Integration | 16/10/2023 | 17/6/2026 | The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so. | |
| Analizada | Alta (8.8) | 0.24% | — | Heiglandreas Authldap | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Andreas Heigl authLdap plugin <= 2.5.8 versions. | |
| Analizada | Media (4.8) | 0.37% | — | Heiglandreas Authldap | 29/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Andreas Heigl authLdap plugin <= 2.5.9 versions. | |
| Modificada | Media (4.3) | 0.75% | — | Lemonldap-ng Lemonldap\ | 29/9/2023 | 17/6/2026 | A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770. | |
| Modificada | Media (6.5) | 0.91% | — | Miniorange Active Directory Integration / Ldap Integration | 27/9/2023 | 17/6/2026 | The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the… | |
| Modificada | Alta (7.5) | 0.53% | — | Miniorange Active Directory Integration / Ldap Integration | 29/6/2023 | 17/6/2026 | The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to… | |
| Modificada | Media (6.5) | 0.42% | — | Miniorange Active Directory Integration / Ldap Integration | 9/6/2023 | 17/6/2026 | The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user supplied… | |
| Modificada | Media (4.9) | 0.85% | — | Miniorange Active Directory Integration / Ldap Integration | 9/6/2023 | 17/6/2026 | The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Modificada | Alta (7.5) | 1.9% | — | OpenldapRedhat Enterprise LinuxApple MacosNetapp Active IQ Unified Manager+7 | 30/5/2023 | 17/6/2026 | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. | |
| Modificada | Crítica (9.8) | 0.78% | — | Lemonldap-ng Lemonldap\ | 29/5/2023 | 17/6/2026 | In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to bypass a Require directive. | |
| Modificada | Alta (7.5) | 0.82% | — | Miniorange Active Directory Integration / Ldap Integration | 15/5/2023 | 17/6/2026 | The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure. |