Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.73% | — | Lemonldap-ng Lemonldap\ | 16/4/2023 | 17/6/2026 | In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically. | |
| Modificada | Crítica (9.8) | 0.96% | — | Lemonldap-ng Lemonldap\ | 31/3/2023 | 17/6/2026 | An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny session creation after the store step does not deny an AuthBasic session. | |
| Modificada | Alta (7.5) | 0.35% | — | Forgerock Ldap Connector | 29/3/2023 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Windows, MacOS, Linux allows Remote Services with Stolen Credentials.This issue affects OpenIDM and Java Remote Connector Server (RCS): from 1.5.20.9 through 1.5.20.13. | |
| Analizada | Crítica (9.8) | 1.5% | — | Apache Kerby Ldap Backend | 20/2/2023 | 17/6/2026 | An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. | |
| Modificada | Alta (8.1) | 0.42% | — | Lemonldap-ng Apache\Debian Linux | 27/1/2023 | 17/6/2026 | In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix. | |
| Modificada | Alta (8.1) | 0.44% | — | Lemonldap-ng Apache\Debian Linux | 27/1/2023 | 17/6/2026 | In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix. | |
| Modificada | Alta (7.5) | 0.56% | — | Miniorange Ldap Integration With Active Directory AND Openldap | 17/1/2023 | 17/6/2026 | The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database. | |
| Modificada | Crítica (9.8) | 0.85% | — | Ttrrs-auth-ldap Project Ttrrs-auth-ldap | 7/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in hydrian TTRSS-Auth-LDAP. Affected by this issue is some unknown functionality of the component Username Handler. The manipulation leads to ldap injection. Upgrading to version 2.0b1 is able to address this issue. The patch is identified as… | |
| Modificada | Media (6.1) | 0.54% | — | Ldapcherry Project Ldapcherry | 5/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in kakwa LdapCherry up to 0.x. Affected is an unknown function of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0.0 is able to address this issue. The patch… | |
| Modificada | Alta (7.8) | 0.33% | — | Opensuse Openldap2 | 9/11/2022 | 17/6/2026 | A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root. This issue affects: openSUSE Factory openldap2 versions prior to 2.6.3-404.1. | |
| Modificada | Alta (7.5) | 0.52% | — | Ldap WP Login / Active Directory Integration Project Ldap WP Login / Active Directory Integration | 26/9/2022 | 17/6/2026 | The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated attackers to update them. Attackers could set their own LDAP server to be used to authenticated… | |
| Modificada | Crítica (9.8) | 0.66% | — | Forgerock Ldap Connector | 19/9/2022 | 17/6/2026 | When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS) | |
| Modificada | Crítica (9.8) | 1.2% | — | Lemonldap-ng Lemonldap\Debian Linux | 18/7/2022 | 17/6/2026 | An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in,… | |
| Modificada | Alta (7.5) | 0.77% | — | Lemonldap-ng Lemonldap\Debian Linux | 18/7/2022 | 17/6/2026 | In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. | |
| Modificada | Media (5.3) | 1.3% | — | Ldap-account-manager Ldap Account ManagerDebian Linux | 27/6/2022 | 17/6/2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the user name field at login could be used to enumerate LDAP data. This is only the case for LDAP search configuration. This issue has been fixed in version 8.0. | |
| Modificada | Alta (7.8) | 0.44% | — | Ldap-account-manager Ldap Account ManagerDebian Linux | 27/6/2022 | 17/6/2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows interpretation of .php (and .php5/.php4/.phpt/etc) files. An attacker capable of writing files under… | |
| Modificada | Alta (8.8) | 2.3% | — | Ldap-account-manager Ldap Account ManagerDebian Linux | 27/6/2022 | 17/6/2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the… | |
| Modificada | Media (6.1) | 0.27% | — | Ldap-account-manager Ldap Account ManagerDebian Linux | 27/6/2022 | 17/6/2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the session files include the LDAP user name and password in clear text if the PHP OpenSSL extension is not installed or encryption is disabled by configuration.… | |
| Modificada | Alta (8.1) | 2.5% | — | Ldap-account-manager Ldap Account ManagerDebian Linux | 27/6/2022 | 17/6/2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 There are cases where LAM instantiates objects from arbitrary classes. An attacker can inject the first constructor argument. This can lead to code execution if… | |
| Modificada | Media (6.5) | 1.9% | — | Python-ldap | 18/6/2022 | 17/6/2026 | python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a… | |
| Modificada | Crítica (9.8) | 64% | — | OpenldapDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+4 | 4/5/2022 | 17/6/2026 | In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping. | |
| Modificada | Media (4.8) | 1.1% | — | Ldap-account-manager Ldap Account ManagerDebian Linux | 15/4/2022 | 17/6/2026 | LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks. An authenticated user can store XSS payloads in the… | |
| Modificada | Baja (2.7) | 0.69% | — | Owncloud User Ldap | 8/9/2021 | 17/6/2026 | Server Side Request Forgery (SSRF) vulnerability exists in owncloud/user_ldap < 0.15.4 in the settings of the user_ldap app. Administration role is necessary for exploitation. | |
| Modificada | Alta (8.8) | 1.8% | — | Lemonldap-ng Lemonldap\Debian Linux | 30/7/2021 | 17/6/2026 | An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users. | |
| Modificada | Alta (7.5) | 2.7% | — | OpenldapRedhat Jboss Core ServicesRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB Server+3 | 28/5/2021 | 17/6/2026 | A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability. |