Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.42% | — | Logpoint Saml Authentication | 27/5/2024 | 17/6/2026 | An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the state field of a SAML SSO-URL response, and the file corresponding to this filename will ultimately be deleted. This can lead to a SAML Authentication login outage. | |
| Analizada | Crítica (9.1) | 1.8% | — | Apereo Central Authentication Service | 23/5/2024 | 17/6/2026 | The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack | |
| Analizada | Media (6.2) | 0.27% | — | Cisco DUO Authentication FOR Windows Logon AND RDP | 6/3/2024 | 17/6/2026 | A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to invalidate locally created trusted sessions after a reboot of the affected device. An… | |
| Analizada | Media (5.5) | 0.11% | — | Cisco DUO Authentication FOR Windows Logon AND RDP | 6/3/2024 | 17/6/2026 | A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. This vulnerability is due to improper storage of an unencrypted registry key in certain logs. An attacker could… | |
| Analizada | Alta (7.8) | 0.34% | — | Thalesgroup Safenet Authentication Client | 27/2/2024 | 17/6/2026 | A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access. | |
| Analizada | Alta (7.8) | 0.17% | — | Thalesgroup Safenet Authentication Client | 27/2/2024 | 17/6/2026 | A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access. | |
| Analizada | Alta (8.1) | 0.80% | — | Discourse Microsoft Authentication | 21/2/2024 | 17/6/2026 | `discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft-auth` plugin enabled, an attack can potentially take control of a victim's Discourse account. Sites that have configured their application's account type to any options other than `Accounts in this… | |
| Aplazada | Alta (7.8) | 0.35% | — | Vmware Enhanced Authentication Plug-inAI | 20/2/2024 | 17/6/2026 | Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP session when initiated by a privileged domain user on the same system. | |
| Aplazada | Crítica (9.6) | 1.3% | — | Vmware Enhanced Authentication Plug-inAI | 20/2/2024 | 17/6/2026 | Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory… | |
| Modificada | Media (6.1) | 0.45% | — | Nextcloud SSO & Saml Authentication | 18/1/2024 | 17/6/2026 | Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or 6.0.1. There are no known workarounds for… | |
| Modificada | Alta (8.2) | 0.46% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Carbon Identity Application Authentication Endpoint+1 | 15/12/2023 | 17/6/2026 | Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: Attacker should have: When all preconditions are met, a malicious actor could use JIT provisioning… | |
| Analizada | Media (6.1) | 0.60% | — | Jenkins Openid Connect Authentication | 13/12/2023 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks. | |
| Modificada | Crítica (9.8) | 0.94% | — | Apereo Central Authentication Service | 9/11/2023 | 17/6/2026 | Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the… | |
| Modificada | Alta (7.3) | 0.20% | — | Samsung Memory Card & UFD Authentication | 18/9/2023 | 17/6/2026 | A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows to exploit this vulnerability.) | |
| Modificada | Media (5.5) | 0.17% | — | IBM Sterling External Authentication Server | 5/9/2023 | 17/6/2026 | IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing during operations. IBM X-Force ID: 252139. | |
| Modificada | Media (5.5) | 0.19% | — | IBM Sterling External Authentication ServerIBM Sterling Secure Proxy | 5/9/2023 | 17/6/2026 | IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585. | |
| Modificada | Media (5.5) | 0.14% | — | Thalesgroup Safenet Authentication Service | 16/8/2023 | 17/6/2026 | Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via local privilege escalation. | |
| Modificada | Media (5.9) | 0.59% | — | Jenkins Tuleap Authentication | 16/8/2023 | 17/6/2026 | Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token. | |
| Modificada | Media (5.4) | 0.70% | — | Jenkins Gitlab Authentication | 26/7/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker's account. | |
| Modificada | Media (6.5) | 0.48% | — | DUO Authentication Proxy | 12/7/2023 | 17/6/2026 | A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability exists because certain unencrypted credentials are stored. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.5) | 0.50% | — | Apereo Central Authentication Service | 27/6/2023 | 17/6/2026 | Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake or a special HTTP header, such as “ssl_client_cert”. When checking the validity of the provided… | |
| Modificada | Media (4.6) | 0.25% | — | Cisco DUOCisco DUO Authentication FOR Windows Logon AND RDP | 5/4/2023 | 17/6/2026 | A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected macOS or Windows device. This vulnerability… | |
| Modificada | Media (4.3) | 0.40% | — | Cloudfoundry User Account AND Authentication | 28/3/2023 | 17/6/2026 | This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an external identity provider is linked to the UAA, a refresh token is issued to a client on behalf of a user from that identity provider, the administrator of the UAA deactivates the identity provider… | |
| Analizada | Crítica (9.8) | 0.86% | — | Microfocus Netiq Advanced Authentication | 15/3/2023 | 17/6/2026 | Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2 | |
| Modificada | Media (5.5) | 0.12% | — | IBM Sterling External Authentication ServerIBM Sterling Secure Proxy | 8/2/2023 | 17/6/2026 | IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during installation that could allow a local attacker to decrypt sensitive information. IBM X-Force ID: 231373. |