Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

290 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.75%—Appgenix Infotech Firebase OTP AuthenticationAI13/12/202417/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Appgenix Infotech Firebase OTP Authentication authentication-via-otp-using-firebase allows Authentication Bypass.This issue affects Firebase OTP Authentication: from n/a through <= 1.0.1.
AnalizadaMedia (5.3)0.62%—Apereo Central Authentication Service14/11/202417/6/2026
A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.…
AnalizadaMedia (6.3)0.75%—Apereo Central Authentication Service14/11/202417/6/2026
A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be…
AnalizadaMedia (5.3)0.36%—Apereo Central Authentication Service14/11/202417/6/2026
A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may…
AnalizadaAlta (8.8)0.64%—Jenkins Openid Connect Authentication13/11/202417/6/2026
Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.
AplazadaMedia (4.8)0.32%—Secusuite Secure Client Authentication SCA ServerAI12/11/202417/6/2026
An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number.
AnalizadaMedia (6.9)0.51%—Lifplatforms LIF Authentication Server4/10/202417/6/2026
Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct code. If the attacker knew the email of…
AnalizadaAlta (8.1)0.63%—Jenkins Openid Connect Authentication2/10/202417/6/2026
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.
AnalizadaAlta (8.1)0.63%—Jenkins Openid Connect Authentication2/10/202417/6/2026
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.
ModificadaCrítica (9.3)0.58%—Watchguard Authentication Gateway25/9/20248/8/2026
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and…
ModificadaCrítica (9.3)1.2%—Watchguard Authentication GatewayWatchguard Single Sign-on Client25/9/20248/8/2026
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an…
ModificadaAlta (7.5)0.50%—Mfasoft Secure Authentication Server16/9/202417/6/2026
An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain access to user tokens without authentication. The is a brute-force attack on the serial parameter by…
ModificadaAlta (7.5)0.56%—Opendaylight Authentication, Authorization AND Accounting15/9/202417/6/2026
An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.
AnalizadaMedia (5.5)0.11%—Cisco DUO Authentication FOR Epic4/9/202417/6/2026
A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This vulnerability is due to improper storage of an unencrypted registry key. A low-privileged attacker could exploit this vulnerability by viewing or querying…
AnalizadaMedia (5.3)0.24%—Youtag Two-factor Authentication31/8/202417/6/2026
The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with…
AnalizadaAlta (8.2)0.29%—Microfocus Netiq Advanced Authentication28/8/202417/6/2026
A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before 6.3.5.1
AnalizadaAlta (8.8)0.18%—Microfocus Netiq Advanced Authentication28/8/202417/6/2026
Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices. This issue affects NetIQ Advance Authentication versions before 6.3.5.1
AnalizadaAlta (7.2)0.53%—Microfocus Netiq Advanced Authentication28/8/202417/6/2026
A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.
AnalizadaCrítica (9.9)0.23%—Microfocus Netiq Advanced Authentication28/8/202417/6/2026
A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This issue impacts all NetIQ Advance Authentication before 6.3.5.1
AnalizadaMedia (5.5)0.16%—Microfocus Netiq Advanced Authentication28/8/202417/6/2026
A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication version before 6.3.5.1
AnalizadaMedia (6.5)0.21%—Microfocus Netiq Advanced Authentication28/8/202417/6/2026
A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1
ModificadaMedia (5.5)0.83%—Microsoft Authentication LibraryMicrosoft Azure Identity SDK11/6/202420/7/2026
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
ModificadaAlta (7.5)3.3%—Securenvoy Multi-factor Authentication Solutions10/6/202417/6/2026
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint.…
ModificadaMedia (6.5)0.59%—Born05 Two-factor Authentication6/6/202417/6/2026
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.
ModificadaAlta (8.1)0.83%—Born05 Two-factor Authentication6/6/202417/6/2026
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.