Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.75% | — | Appgenix Infotech Firebase OTP AuthenticationAI | 13/12/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Appgenix Infotech Firebase OTP Authentication authentication-via-otp-using-firebase allows Authentication Bypass.This issue affects Firebase OTP Authentication: from n/a through <= 1.0.1. | |
| Analizada | Media (5.3) | 0.62% | — | Apereo Central Authentication Service | 14/11/2024 | 17/6/2026 | A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (6.3) | 0.75% | — | Apereo Central Authentication Service | 14/11/2024 | 17/6/2026 | A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be… | |
| Analizada | Media (5.3) | 0.36% | — | Apereo Central Authentication Service | 14/11/2024 | 17/6/2026 | A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Alta (8.8) | 0.64% | — | Jenkins Openid Connect Authentication | 13/11/2024 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login. | |
| Aplazada | Media (4.8) | 0.32% | — | Secusuite Secure Client Authentication SCA ServerAI | 12/11/2024 | 17/6/2026 | An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number. | |
| Analizada | Media (6.9) | 0.51% | — | Lifplatforms LIF Authentication Server | 4/10/2024 | 17/6/2026 | Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct code. If the attacker knew the email of… | |
| Analizada | Alta (8.1) | 0.63% | — | Jenkins Openid Connect Authentication | 2/10/2024 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins. | |
| Analizada | Alta (8.1) | 0.63% | — | Jenkins Openid Connect Authentication | 2/10/2024 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins. | |
| Modificada | Crítica (9.3) | 0.58% | — | Watchguard Authentication Gateway | 25/9/2024 | 8/8/2026 | Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and… | |
| Modificada | Crítica (9.3) | 1.2% | — | Watchguard Authentication GatewayWatchguard Single Sign-on Client | 25/9/2024 | 8/8/2026 | An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an… | |
| Modificada | Alta (7.5) | 0.50% | — | Mfasoft Secure Authentication Server | 16/9/2024 | 17/6/2026 | An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain access to user tokens without authentication. The is a brute-force attack on the serial parameter by… | |
| Modificada | Alta (7.5) | 0.56% | — | Opendaylight Authentication, Authorization AND Accounting | 15/9/2024 | 17/6/2026 | An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information. | |
| Analizada | Media (5.5) | 0.11% | — | Cisco DUO Authentication FOR Epic | 4/9/2024 | 17/6/2026 | A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This vulnerability is due to improper storage of an unencrypted registry key. A low-privileged attacker could exploit this vulnerability by viewing or querying… | |
| Analizada | Media (5.3) | 0.24% | — | Youtag Two-factor Authentication | 31/8/2024 | 17/6/2026 | The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with… | |
| Analizada | Alta (8.2) | 0.29% | — | Microfocus Netiq Advanced Authentication | 28/8/2024 | 17/6/2026 | A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before 6.3.5.1 | |
| Analizada | Alta (8.8) | 0.18% | — | Microfocus Netiq Advanced Authentication | 28/8/2024 | 17/6/2026 | Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices. This issue affects NetIQ Advance Authentication versions before 6.3.5.1 | |
| Analizada | Alta (7.2) | 0.53% | — | Microfocus Netiq Advanced Authentication | 28/8/2024 | 17/6/2026 | A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1. | |
| Analizada | Crítica (9.9) | 0.23% | — | Microfocus Netiq Advanced Authentication | 28/8/2024 | 17/6/2026 | A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This issue impacts all NetIQ Advance Authentication before 6.3.5.1 | |
| Analizada | Media (5.5) | 0.16% | — | Microfocus Netiq Advanced Authentication | 28/8/2024 | 17/6/2026 | A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication version before 6.3.5.1 | |
| Analizada | Media (6.5) | 0.21% | — | Microfocus Netiq Advanced Authentication | 28/8/2024 | 17/6/2026 | A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1 | |
| Modificada | Media (5.5) | 0.83% | — | Microsoft Authentication LibraryMicrosoft Azure Identity SDK | 11/6/2024 | 20/7/2026 | Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 3.3% | — | Securenvoy Multi-factor Authentication Solutions | 10/6/2024 | 17/6/2026 | Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint.… | |
| Modificada | Media (6.5) | 0.59% | — | Born05 Two-factor Authentication | 6/6/2024 | 17/6/2026 | The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. | |
| Modificada | Alta (8.1) | 0.83% | — | Born05 Two-factor Authentication | 6/6/2024 | 17/6/2026 | The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP. |