Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.83% | — | Jenkins Saml Single Sign ON | 16/5/2023 | 17/6/2026 | Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML. | |
| Modificada | Alta (8.8) | 0.68% | — | Jenkins Saml Single Sign ON | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML. | |
| Modificada | Crítica (9.8) | 0.46% | — | Componentspace Saml | 24/3/2023 | 9/7/2026 | ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion between entities within a trust… | |
| Modificada | Alta (7.5) | 0.96% | — | Saml Project Saml | 22/3/2023 | 17/6/2026 | The crewjam/saml go library contains a partial implementation of the SAML standard in golang. Prior to version 0.4.13, the package's use of `flate.NewReader` does not limit the size of the input. The user can pass more than 1 MB of data in the HTTP request to the processing functions, which will be decompressed… | |
| Modificada | Alta (7.5) | 0.58% | — | Mendix Saml | 14/3/2023 | 17/6/2026 | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.2.0 < V2.3.0), Mendix SAML (Mendix 9 latest compatible, New Track) (All versions >= V3.1.9 < V3.3.1), Mendix SAML (Mendix 9 latest compatible, Upgrade… | |
| Modificada | Media (5.3) | 0.96% | — | Gosaml2 Project Gosaml2 | 3/3/2023 | 17/6/2026 | gosaml2 is a Pure Go implementation of SAML 2.0. SAML Service Providers using this library for SAML authentication support are likely susceptible to Denial of Service attacks. A bug in this library enables attackers to craft a `deflate`-compressed request which will consume significantly more memory during processing… | |
| Modificada | Media (6.5) | 0.52% | — | Php-saml-sp Project Php-saml-sp | 21/2/2023 | 17/6/2026 | php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML external entities was silently enabled via \LIBXML_DTDLOAD | \LIBXML_DTDATTR. | |
| Modificada | Media (6.1) | 0.61% | — | Miniorange Saml SP Single Sign ON | 30/1/2023 | 17/6/2026 | The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the redirect parameter to its SSO login endpoint points to an internal site URL, making… | |
| Modificada | Media (5.4) | 0.56% | — | Simplesamlphp-module-openidprovider | 17/1/2023 | 16/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in simplesamlphp simplesamlphp-module-openidprovider up to 0.8.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file templates/trust.tpl.php. The manipulation of the argument StateID leads to cross site… | |
| Modificada | Media (6.1) | 0.41% | — | Moodle Saml Authentication | 12/1/2023 | 17/6/2026 | Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors. | |
| Modificada | Media (6.1) | 0.47% | — | Mendix Saml | 10/1/2023 | 17/6/2026 | A vulnerability has been identified in Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.3.4), Mendix SAML (Mendix 9 compatible, New Track) (All versions >= V3.3.0 < V3.3.9), Mendix SAML (Mendix 9 compatible, Upgrade Track) (All versions >= V3.3.0 < V3.3.8). The affected module is vulnerable to reflected… | |
| Modificada | Media (6.1) | 0.51% | — | Simplesamlphp Information Cards Module | 9/1/2023 | 16/6/2026 | A vulnerability was found in Information Cards Module on simpleSAMLphp and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 1.0 is able to address this issue. The identifier of the patch is… | |
| Modificada | Media (6.1) | 0.64% | — | Simplesamlphp-module-openid | 1/1/2023 | 16/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in SimpleSAMLphp simplesamlphp-module-openid. Affected is an unknown function of the file templates/consumer.php of the component OpenID Handler. The manipulation of the argument AuthState leads to cross site scripting. It is… | |
| Modificada | Media (5.3) | 0.30% | — | Robotsandpencils Go-saml | 28/12/2022 | 17/6/2026 | XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input. | |
| Modificada | Alta (7.5) | 0.77% | — | Auth0 Passport-wsfed-saml2 | 13/12/2022 | 17/6/2026 | Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker may be able to bypass WSFed authentication on a website using passport-wsfed-saml2. A successful attack requires that the attacker is in possession of an arbitrary IDP… | |
| Modificada | Crítica (9.8) | 2.3% | — | Saml Project Saml | 28/11/2022 | 17/6/2026 | The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version. | |
| Modificada | Crítica (9.8) | 0.75% | — | Mendix Saml | 8/11/2022 | 17/6/2026 | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.0 < V1.17.2), Mendix SAML (Mendix 8 compatible) (All versions < V2.3.0), Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.3.2), Mendix SAML (Mendix 9… | |
| Modificada | Alta (8.1) | 0.66% | — | Node Saml Project Node Saml | 13/10/2022 | 17/6/2026 | node SAML is a SAML 2.0 library based on the SAML implementation of passport-saml. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully… | |
| Modificada | Alta (8.1) | 3.4% | 💥 PoC | Passport-saml Project Passport-saml | 12/10/2022 | 17/6/2026 | Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the… | |
| Modificada | Crítica (9.8) | 1.2% | — | Mendix Saml | 13/9/2022 | 17/6/2026 | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All versions < V2.3.0), Mendix SAML (Mendix 9 compatible, New Track) (All versions < V3.3.1), Mendix SAML (Mendix 9 compatible, Upgrade Track) (All versions < V3.3.0). Affected versions… | |
| Modificada | Media (6.1) | 0.57% | — | Mendix Saml | 14/6/2022 | 17/6/2026 | A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compatible) (All versions < V2.2.2), Mendix SAML Module (Mendix 9 compatible) (All versions < V3.2.3). In certain configurations SAML module is vulnerable to Cross Site Scripting (XSS)… | |
| Modificada | Alta (7.5) | 1.0% | — | Mendix Saml | 14/6/2022 | 17/6/2026 | A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compatible) (All versions < V2.2.2), Mendix SAML Module (Mendix 9 compatible) (All versions < V3.2.3). The affected module is vulnerable to XML External Entity (XXE) attacks due to… | |
| Modificada | Alta (8.8) | 0.59% | — | Drupal Saml SP 2.0 Single Sign ON | 3/6/2022 | 17/6/2026 | Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An attacker with access to a HTTP-request intercepting method is able to bypass authentication and authorization by removing the SAML Assertion Signature - impersonating… | |
| Modificada | Media (6.1) | 0.97% | — | Simplesamlphp Authentication Project Simplesamlphp Authentication | 9/9/2021 | 17/6/2026 | The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simplesamlphp-authentication.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.0. | |
| Modificada | Alta (8.8) | 0.81% | — | Jenkins Saml | 31/8/2021 | 17/6/2026 | Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins. |