Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
186 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Saml Single Sign ON | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers to send an HTTP POST request with JSON body containing attacker-specified content, to miniOrange's API for sending emails. | |
| Modificada | Baja (3.7) | 0.24% | — | Jenkins Saml Single Sign ON | 16/5/2023 | 17/6/2026 | Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections. | |
| Modificada | Media (4.8) | 0.21% | — | Jenkins Saml Single Sign ON | 16/5/2023 | 17/6/2026 | Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections. | |
| Modificada | Alta (8.8) | 0.83% | — | Jenkins Saml Single Sign ON | 16/5/2023 | 17/6/2026 | Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML. | |
| Modificada | Alta (8.8) | 0.68% | — | Jenkins Saml Single Sign ON | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML. | |
| Modificada | Media (5.4) | 0.70% | 💥 PoC | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container Platform | 29/3/2023 | 17/6/2026 | A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users. | |
| Modificada | Media (6.1) | 0.40% | — | Redhat Keycloak Node.js AdapterRedhat Single Sign-on | 27/3/2023 | 17/6/2026 | A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function. | |
| Modificada | Media (6.5) | 0.33% | — | Miniorange Oauth Single Sign ON | 27/3/2023 | 17/6/2026 | The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack | |
| Modificada | Media (6.5) | 0.44% | — | Miniorange Oauth Single Sign ON | 27/3/2023 | 17/6/2026 | The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP),… | |
| Modificada | Alta (7.5) | 0.60% | — | Redhat Build OF QuarkusRedhat Integration Camel FOR Spring BootRedhat Integration Camel KRedhat Integration Service Registry+6 | 23/2/2023 | 17/6/2026 | The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol. | |
| Modificada | Media (6.1) | 0.61% | — | Miniorange Saml SP Single Sign ON | 30/1/2023 | 17/6/2026 | The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the redirect parameter to its SSO login endpoint points to an internal site URL, making… | |
| Modificada | Alta (7.5) | 0.44% | — | Oauth Client Single Sign ON Project Oauth Client Single Sign ON | 26/9/2022 | 17/6/2026 | The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email… | |
| Modificada | Alta (7.5) | 0.86% | — | Redhat WildflyRedhat AMQRedhat AMQ OnlineRedhat Integration Camel K+4 | 13/9/2022 | 17/6/2026 | A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain. | |
| Modificada | Media (4.9) | 0.89% | — | Redhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Single Sign-on+5 | 1/9/2022 | 17/6/2026 | A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations. | |
| Modificada | Baja (3.8) | 0.68% | — | Redhat Single Sign-on | 1/9/2022 | 17/6/2026 | A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality. | |
| Modificada | Alta (7.5) | 1.6% | — | Redhat Openshift Application RuntimesRedhat Single Sign-onRedhat UndertowNetapp Active IQ Unified Manager+3 | 31/8/2022 | 17/6/2026 | A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet… | |
| Modificada | Alta (7.5) | 1.3% | — | Redhat Build OF QuarkusRedhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+6 | 31/8/2022 | 17/6/2026 | A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629. | |
| Modificada | Media (5.4) | 3.1% | — | Redhat KeycloakRedhat Single Sign-on | 26/8/2022 | 17/6/2026 | A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack. | |
| Modificada | Alta (7.5) | 1.5% | — | Redhat Integration Camel KRedhat Integration Camel QuarkusRedhat Single Sign-onRedhat Xnio | 26/8/2022 | 17/6/2026 | A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. This flaw allows an attacker to send flawed requests to a server, possibly causing log contention-related performance concerns or an unwanted disk fill-up. | |
| Modificada | Alta (7.5) | 1.6% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat UndertowNetapp Cloud Secure Agent+2 | 26/8/2022 | 17/6/2026 | A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks. | |
| Modificada | Media (5.3) | 2.1% | 💥 PoC | Redhat KeycloakRedhat Single Sign-on | 26/8/2022 | 17/6/2026 | A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password. | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat KeycloakRedhat Single Sign-on | 26/8/2022 | 17/6/2026 | A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow. | |
| Modificada | Media (6.8) | 1.1% | — | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container Platform | 23/8/2022 | 17/6/2026 | A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authorization header with the user's credentials. The highest threat from this… | |
| Modificada | Alta (7.5) | 1.7% | — | Redhat FuseRedhat Integration Camel KRedhat Integration Camel QuarkusRedhat Jboss Enterprise Application Platform+3 | 23/8/2022 | 17/6/2026 | A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability. | |
| Modificada | Alta (7.2) | 0.97% | — | Redhat KeycloakRedhat Single Sign-on | 5/8/2022 | 17/6/2026 | An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled |