Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Passport-saml Project Passport-saml | 27/8/2021 | 17/6/2026 | Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. Prior to version 3.1.0, a malicious SAML payload can require transforms that consume significant system resources to process, thereby resulting in reduced or denied service. This would be an effective way to perform a… | |
| Modificada | Alta (7.5) | 1.00% | — | Miniorange Saml | 13/8/2021 | 17/6/2026 | The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys. | |
| Modificada | Media (5.4) | 0.50% | — | Miniorange Saml | 13/8/2021 | 17/6/2026 | The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS. | |
| Modificada | Crítica (9.8) | 1.5% | — | Atlassian Saml Single Sign ON | 2/8/2021 | 17/6/2026 | The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided). The fixed versions are for Jira: 3.6.6.1, 4.0.12, 5.0.5; for Confluence 3.6.6, 4.0.12, 5.0.5; for Bitbucket 2.5.9, 3.6.6, 4.0.12, 5.0.5;… | |
| Modificada | Alta (8.8) | 0.60% | — | Mendix Saml | 8/6/2021 | 17/6/2026 | A vulnerability has been identified in Mendix SAML Module (All versions < V2.1.2). The configuration of the SAML module does not properly check various restrictions and validations imposed by an identity provider. This could allow a remote authenticated attacker to escalate privileges. | |
| Modificada | Alta (7.5) | 1.7% | — | Gosaml2 Project Gosaml2 | 30/4/2021 | 17/6/2026 | This affects all versions <0.7.0 of package github.com/russellhaering/gosaml2. There is a crash on nil-pointer dereference caused by sending malformed XML signatures. | |
| Modificada | Media (6.5) | 1.3% | — | Fusionauth Saml V2 | 22/4/2021 | 17/6/2026 | FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely. | |
| Modificada | Media (6.5) | 1.3% | 💥 PoC | Pysaml2 Project Pysaml2Debian Linux | 21/1/2021 | 17/6/2026 | PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. Users of pysaml2 that use the default CryptoBackendXmlSec1 backend and need to verify signed SAML documents are impacted. PySAML2 does not ensure that a signed… | |
| Modificada | Media (6.5) | 1.1% | — | Pysaml2 Project Pysaml2 | 21/1/2021 | 17/6/2026 | PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not… | |
| Modificada | Crítica (9.8) | 4.9% | — | GrafanaSaml Project SamlRedhat Openshift Container PlatformRedhat Openshift Service Mesh+2 | 21/12/2020 | 17/6/2026 | A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. | |
| Modificada | Crítica (9.1) | 2.9% | — | Fusionauth Samlv2 | 2/10/2020 | 17/6/2026 | FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack". | |
| Modificada | Baja (3.1) | 0.92% | — | Simplesamlphp | 21/4/2020 | 17/6/2026 | SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. The module controller in `SimpleSAML\Module` that processes requests for pages hosted by modules, has code to identify paths ending with `.php` and process those as PHP code. If no other suitable way of handling the given path exists… | |
| Modificada | Alta (7.3) | 1.1% | — | Sustainsys Saml2 | 21/4/2020 | 17/6/2026 | In Saml2 Authentication Services for ASP.NET versions before 1.0.2, and between 2.0.0 and 2.6.0, there is a vulnerability in how tokens are validated in some cases. Saml2 tokens are usually used as bearer tokens - a caller that presents a token is assumed to be the subject of the token. There is also support in the… | |
| Modificada | Media (6.8) | 1.5% | — | Sustainsys Saml2 | 25/3/2020 | 17/6/2026 | Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5.0 has a faulty implementation of Token Replay Detection. Token Replay Detection is an important defence in depth measure for Single Sign On solutions. The 2.5.0 version is patched. Note that version… | |
| Modificada | Media (6.1) | 1.4% | — | Miniorange Saml SP Single Sign ON | 17/2/2020 | 17/6/2026 | Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element. | |
| Modificada | Media (5.4) | 0.54% | — | Simplesamlphp | 24/1/2020 | 17/6/2026 | Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be submitted and sent to the system administrator. Starting with SimpleSAMLphp 1.18.0, a new SimpleSAML\Utils\EMail class was introduced to handle sending emails, implemented as a wrapper of an external… | |
| Modificada | Media (5.4) | 0.66% | — | Simplesamlphp | 24/1/2020 | 17/6/2026 | Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and sends them via email to the system administrator, did not properly sanitize the report identifier obtained from the request. This allows an attacker, under specific circumstances, to inject new log… | |
| Modificada | Alta (7.5) | 1.2% | — | Pysaml2 Project Pysaml2Canonical Ubuntu LinuxDebian Linux | 13/1/2020 | 17/6/2026 | PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will… | |
| Modificada | Alta (7.5) | 1.1% | — | Atlassian Saml Single Sign ON | 13/12/2019 | 17/6/2026 | An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbucket, and versions 2.4.0 through 2.5.2 for Bamboo. It allows locally disabled users to reactivate their accounts just by… | |
| Modificada | Alta (8.8) | 3.0% | — | Xmlseclibs Project XmlseclibsDebian LinuxSimplesamlphp | 7/11/2019 | 17/6/2026 | Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message. | |
| Modificada | Alta (7.5) | 0.74% | — | SimplesamlphpDebian Linux | 6/11/2019 | 16/6/2026 | simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages. | |
| Modificada | Alta (7.5) | 1.7% | — | Onelogin Saml SSO | 22/8/2019 | 17/6/2026 | The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users. | |
| Modificada | Alta (7.5) | 1.2% | — | Zendesk Samlr | 26/7/2019 | 17/6/2026 | Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name. | |
| Modificada | Media (6.1) | 1.1% | — | Miniorange Saml SP Single Sign ON | 24/6/2019 | 17/6/2026 | In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post. | |
| Modificada | Crítica (9.8) | 2.4% | — | Omniauth Saml | 17/4/2019 | 17/6/2026 | OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service… |