Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

290 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.42%—Logpoint Saml Authentication27/5/202417/6/2026
An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the state field of a SAML SSO-URL response, and the file corresponding to this filename will ultimately be deleted. This can lead to a SAML Authentication login outage.
AnalizadaCrítica (9.1)1.8%—Apereo Central Authentication Service23/5/202417/6/2026
The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack
AnalizadaMedia (6.2)0.27%—Cisco DUO Authentication FOR Windows Logon AND RDP6/3/202417/6/2026
A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to invalidate locally created trusted sessions after a reboot of the affected device. An…
AnalizadaMedia (5.5)0.11%—Cisco DUO Authentication FOR Windows Logon AND RDP6/3/202417/6/2026
A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. This vulnerability is due to improper storage of an unencrypted registry key in certain logs. An attacker could…
AnalizadaAlta (7.8)0.34%—Thalesgroup Safenet Authentication Client27/2/202417/6/2026
A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access.
AnalizadaAlta (7.8)0.17%—Thalesgroup Safenet Authentication Client27/2/202417/6/2026
A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access.
AnalizadaAlta (8.1)0.80%—Discourse Microsoft Authentication21/2/202417/6/2026
`discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft-auth` plugin enabled, an attack can potentially take control of a victim's Discourse account. Sites that have configured their application's account type to any options other than `Accounts in this…
AplazadaAlta (7.8)0.35%—Vmware Enhanced Authentication Plug-inAI20/2/202417/6/2026
Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP session when initiated by a privileged domain user on the same system.
AplazadaCrítica (9.6)1.3%—Vmware Enhanced Authentication Plug-inAI20/2/202417/6/2026
Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory…
ModificadaMedia (6.1)0.45%—Nextcloud SSO & Saml Authentication18/1/202417/6/2026
Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or 6.0.1. There are no known workarounds for…
ModificadaAlta (8.2)0.46%—Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Carbon Identity Application Authentication Endpoint+115/12/202317/6/2026
Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: Attacker should have: When all preconditions are met, a malicious actor could use JIT provisioning…
AnalizadaMedia (6.1)0.60%—Jenkins Openid Connect Authentication13/12/202317/6/2026
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
ModificadaCrítica (9.8)0.94%—Apereo Central Authentication Service9/11/202317/6/2026
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the…
ModificadaAlta (7.3)0.20%—Samsung Memory Card & UFD Authentication18/9/202317/6/2026
A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows to exploit this vulnerability.)
ModificadaMedia (5.5)0.17%—IBM Sterling External Authentication Server5/9/202317/6/2026
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain privileged information due to inadequate memory clearing during operations. IBM X-Force ID: 252139.
ModificadaMedia (5.5)0.19%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy5/9/202317/6/2026
IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585.
ModificadaMedia (5.5)0.14%—Thalesgroup Safenet Authentication Service16/8/202317/6/2026
Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via local privilege escalation.
ModificadaMedia (5.9)0.59%—Jenkins Tuleap Authentication16/8/202317/6/2026
Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.
ModificadaMedia (5.4)0.70%—Jenkins Gitlab Authentication26/7/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker's account.
ModificadaMedia (6.5)0.48%—DUO Authentication Proxy12/7/202317/6/2026
A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability exists because certain unencrypted credentials are stored. An attacker could exploit this vulnerability by…
ModificadaAlta (7.5)0.50%—Apereo Central Authentication Service27/6/202317/6/2026
Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake or a special HTTP header, such as “ssl_client_cert”. When checking the validity of the provided…
ModificadaMedia (4.6)0.25%—Cisco DUOCisco DUO Authentication FOR Windows Logon AND RDP5/4/202317/6/2026
A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected macOS or Windows device. This vulnerability…
ModificadaMedia (4.3)0.40%—Cloudfoundry User Account AND Authentication28/3/202317/6/2026
This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an external identity provider is linked to the UAA, a refresh token is issued to a client on behalf of a user from that identity provider, the administrator of the UAA deactivates the identity provider…
AnalizadaCrítica (9.8)0.86%—Microfocus Netiq Advanced Authentication15/3/202317/6/2026
Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2
ModificadaMedia (5.5)0.12%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy8/2/202317/6/2026
IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during installation that could allow a local attacker to decrypt sensitive information. IBM X-Force ID: 231373.