Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

231 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.9%—OpenldapDebian LinuxApple MAC OS XApple Macos+118/5/202117/6/2026
A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.
ModificadaAlta (7.5)64%—OpenldapDebian Linux14/2/202117/6/2026
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.
ModificadaMedia (6.6)0.30%—Opensuse Openldap211/2/202117/6/2026
A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise…
ModificadaAlta (7.5)12%—OpenldapDebian LinuxApple MAC OS XApple Macos+126/1/202117/6/2026
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
ModificadaAlta (7.5)4.3%—OpenldapDebian LinuxApple MAC OS XApple Macos26/1/202117/6/2026
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.
ModificadaAlta (7.5)85%—OpenldapDebian LinuxApple Macos26/1/202117/6/2026
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.
ModificadaAlta (7.5)77%—OpenldapDebian LinuxApple Macos26/1/202117/6/2026
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.
ModificadaAlta (7.5)4.2%—OpenldapDebian LinuxApple MAC OS XApple Macos26/1/202117/6/2026
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.
ModificadaAlta (7.5)4.3%—OpenldapDebian LinuxApple Macos26/1/202117/6/2026
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
ModificadaAlta (7.5)4.3%—OpenldapDebian LinuxApple MAC OS XApple Macos26/1/202117/6/2026
A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
ModificadaAlta (7.5)4.3%—OpenldapDebian LinuxApple MAC OS XApple Macos26/1/202117/6/2026
A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read).
ModificadaAlta (7.5)77%—OpenldapDebian LinuxApple MAC OS XApple Macos26/1/202117/6/2026
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.
ModificadaAlta (7.5)85%—OpenldapDebian LinuxApple MAC OS XApple Macos26/1/202117/6/2026
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).
ModificadaMedia (5.4)1.3%—Phpldapadmin Project PhpldapadminFedoraproject Fedora11/12/202017/6/2026
An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
ModificadaAlta (7.5)2.2%—OpenldapRedhat Enterprise LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware8/12/202017/6/2026
A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service.
ModificadaAlta (8.8)0.97%—Auth0 Ad/ldap Connector6/11/202017/6/2026
ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result in remote code execution or confidential data loss. CSRF exploits may occur if the user visits a malicious page containing CSRF payload on the same machine that has access to the ad-ldap-connector…
ModificadaCrítica (9.8)2.4%—Lemonldap-ng Lemonldap\Debian Linux14/9/202017/6/2026
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
ModificadaAlta (7.8)0.41%—Opensuse Openldap21/9/202017/6/2026
A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SECURITY, SUSE Linux…
ModificadaMedia (4.2)2.5%—OpenldapRedhat Enterprise LinuxOpensuse LeapMcafee Policy Auditor+114/7/202017/6/2026
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.
ModificadaAlta (7.5)4.4%—OpenldapDebian LinuxOpensuse LeapCanonical Ubuntu Linux+1428/4/202017/6/2026
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
ModificadaCrítica (9.8)1.6%—Prosody MOD Auth LdapProsody MOD Auth Ldap2Debian Linux28/1/202017/6/2026
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.
ModificadaAlta (7.5)3.1%—OpenldapDebian Linux2/1/202017/6/2026
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.
ModificadaMedia (6.1)1.6%—Ldap-account-manager Ldap Account ManagerDebian LinuxFedoraproject Fedora5/12/201916/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
ModificadaMedia (6.1)1.6%—Ldap-account-manager Ldap Account ManagerDebian LinuxFedoraproject Fedora5/12/201916/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.
ModificadaMedia (4.3)0.41%—Dash CoreOfficialdapscoin Decentralized Anonymous Payment SystemPivx Private Instant Verified Transactions4/12/201917/6/2026
An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on the local network and on the internet. This is a serious threat to user privacy, since it can possibly leak their IP address and the fact…
Orbitaley — Vulnerabilidades