Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.9% | — | MOD Auth OpenidcDebian LinuxFedoraproject FedoraOpensuse Leap | 20/2/2020 | 17/6/2026 | A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning. | |
| Modificada | Media (6.1) | 1.6% | — | MOD Auth Openidc | 26/11/2019 | 17/6/2026 | A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon. | |
| Modificada | Media (6.1) | 1.3% | — | MOD Auth Openidc | 19/7/2019 | 17/6/2026 | ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecting the user to a phishing page or interacting with the application on behalf of the user. The component is: File: src/mod_auth_openidc.c, Line: 3109. The fixed version is: 2.3.10.2. | |
| Modificada | Crítica (9.8) | 3.0% | — | Ruby-openid | 10/6/2019 | 17/6/2026 | Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their… | |
| Modificada | Crítica (9.8) | 1.5% | — | Lightopenid Project Lightopenid | 10/5/2019 | 17/6/2026 | openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method. | |
| Modificada | Media (6.5) | 1.5% | — | Jenkins Openid | 4/4/2019 | 17/6/2026 | A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins Openid | 4/4/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server. | |
| Modificada | Media (6.1) | 1.3% | — | Openid Connect | 21/3/2019 | 17/6/2026 | Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redirect_uri field in an OAuth authorization request (that results in an error response) with the 'openid' scope and a prompt=none value. This allows phishing attacks against the… | |
| Modificada | Media (4.3) | 1.1% | — | Jenkins Openid Connect Authentication | 6/2/2019 | 17/6/2026 | An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlier in OicSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client… | |
| Modificada | Alta (7.5) | 5.2% | — | MOD Auth Openidc | 12/4/2017 | 17/6/2026 | Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request. | |
| Modificada | Media (6.1) | 0.68% | — | Openidm Project Openidm | 9/4/2017 | 17/6/2026 | OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/. | |
| Modificada | Media (6.1) | 0.94% | — | Openidm Project Openidm | 9/4/2017 | 17/6/2026 | OpenIDM through 4.0.0 and 4.5.0 is vulnerable to persistent cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by a crafted Managed Object Name. | |
| Modificada | Media (6.5) | 1.0% | — | Openidm Project Openidm | 9/4/2017 | 17/6/2026 | In OpenIDM through 4.0.0 before 4.5.0, the info endpoint may leak sensitive information upon a request by the "anonymous" user, as demonstrated by responses with a 200 HTTP status code and a JSON object containing IP address strings. This is related to a missing access-control check in… | |
| Modificada | Alta (8.6) | 4.3% | — | MOD Auth Openidc | 2/3/2017 | 17/6/2026 | The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic. | |
| Modificada | Alta (8.6) | 3.6% | — | MOD Auth Openidc | 2/3/2017 | 17/6/2026 | The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "OIDCUnAuthAction pass" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic. | |
| Modificada | Alta (8.8) | 2.2% | — | Janrain Php-openid | 1/2/2016 | 17/6/2026 | examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal array, which might allow remote attackers to hijack the authentication of arbitrary users via vectors involving a crafted HTTP Host header. | |
| Modificada | Media (6.4) | 1.6% | — | ZendopenidZend Framework | 16/11/2014 | 17/6/2026 | The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 does not verify that the openid_op_endpoint value identifies the same Identity Provider as the provider used in the association handle, which allows remote attackers to… | |
| Modificada | Media (5) | 2.4% | — | ZendrestZend FrameworkZendservice SlideshareZendservice API+6 | 16/11/2014 | 17/6/2026 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before… | |
| Modificada | Media (6.8) | 2.2% | — | ZendrestZend FrameworkZendservice SlideshareZendservice API+6 | 16/11/2014 | 17/6/2026 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before… | |
| Modificada | Media (6.4) | 2.6% | — | ZendrestZend FrameworkZendservice SlideshareZendservice API+6 | 16/11/2014 | 17/6/2026 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before… | |
| Modificada | Alta (7.5) | 2.8% | — | Zend FrameworkZendopenid | 4/9/2014 | 17/6/2026 | The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from… | |
| Modificada | Media (4.3) | 2.1% | — | Fedoraproject FedoraJanrain Ruby-openid | 12/12/2013 | 16/6/2026 | The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. | |
| Modificada | Alta (7.5) | 3.0% | — | Janrain Php-openid | 21/8/2013 | 16/6/2026 | Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via XRDS data containing an external entity declaration in conjunction with an entity reference, related to an… | |
| Modificada | Baja (2.1) | 1.0% | 💥 Exploit | Findingscience MOD Auth Openid | 25/7/2012 | 16/6/2026 | mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids. | |
| Modificada | Media (5.8) | 3.1% | — | KAY Framework Project KAY FrameworkOpenid4javaRedhat Jboss Enterprise Application Platform | 27/1/2012 | 16/6/2026 | message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially… |