Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.0% | — | Jenkins Keycloak Authentication | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows attackers to trick users into logging in to the attacker's account. | |
| Modificada | Crítica (9.8) | 1.2% | — | Jenkins Keycloak Authentication | 26/1/2023 | 17/6/2026 | Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login. | |
| Modificada | Alta (8.8) | 1.2% | — | Jenkins Openid Connect Authentication | 26/1/2023 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login. | |
| Modificada | Media (6.1) | 0.41% | — | Moodle Saml Authentication | 12/1/2023 | 17/6/2026 | Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors. | |
| Modificada | Media (6.3) | 0.50% | — | Microfocus Netiq Advanced Authentication | 28/11/2022 | 17/6/2026 | This update resolves a multi-factor authentication bypass attack | |
| Modificada | Alta (8.8) | 0.29% | — | Miniorange Wordpress Rest API Authentication | 18/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress. | |
| Modificada | Baja (3.3) | 0.18% | — | Intel Wlan Authentication AND Privacy Infrastructure | 11/11/2022 | 17/6/2026 | Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Crítica (9.8) | 2.1% | — | Osuosl Twisted VNC Authentication Proxy | 14/9/2022 | 17/6/2026 | OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerability that could allow a malicious actor to gain unauthorized access to a VNC session or to disconnect a legitimate user from a VNC session. A remote attacker with network access… | |
| Modificada | Crítica (9.8) | 1.3% | — | KB Login Authentication Script Project KB Login Authentication Script | 13/7/2022 | 17/6/2026 | A vulnerability was found in KB Login Authentication Script 1.1 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.7) | 1.0% | — | Thalesgroup Safenet Authentication Client | 24/6/2022 | 17/6/2026 | Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, to overwrite arbitrary files, and potentially achieve arbitrary command execution with high privileges. | |
| Modificada | Media (5.3) | 0.88% | — | IBM Secure External Authentication ServerIBM Sterling Secure Proxy | 17/5/2022 | 17/6/2026 | IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associated with the host due to improper validation of certificates. IBM X-Force ID: 201104. | |
| Modificada | Media (6.5) | 1.7% | — | Lmsdoctor 2 Factor Authentication | 10/5/2022 | 17/6/2026 | A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism. | |
| Modificada | Alta (7.5) | 2.3% | — | Lmsdoctor 2 Factor Authentication | 10/5/2022 | 9/7/2026 | LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts. | |
| Modificada | Media (6.5) | 1.0% | — | Jenkins Gitlab Authentication | 15/3/2022 | 17/6/2026 | Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (4.4) | 0.17% | — | Citrix Federated Authentication Service | 10/3/2022 | 17/6/2026 | Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if… | |
| Modificada | Media (4.3) | 1.0% | — | IBM Sterling External Authentication Server | 24/2/2022 | 17/6/2026 | IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which could be used for an attack. IBM X-Force ID: 220144. | |
| Modificada | Alta (7.5) | 2.0% | — | IBM Sterling External Authentication ServerIBM Sterling Secure Proxy | 23/2/2022 | 17/6/2026 | IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395. | |
| Modificada | Media (6.5) | 0.58% | — | IBM Sterling External Authentication ServerIBM Sterling Secure Proxy | 23/2/2022 | 17/6/2026 | IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty based GUI in the Secure Zone not properly validating the sizes of the form content and/or HTTP headers submitted. A local attacker positioned inside the Secure Zone… | |
| Modificada | Media (5.4) | 0.72% | — | Jenkins Gitlab Authentication | 15/2/2022 | 17/6/2026 | Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after logging in. | |
| Modificada | Alta (7.8) | 0.32% | — | Thalesgroup Safenet Authentication Service Remote Desktop Gateway | 19/1/2022 | 17/6/2026 | A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed. | |
| Modificada | Media (6.1) | 8.2% | — | Apereo Central Authentication Service | 7/12/2021 | 17/6/2026 | Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints. | |
| Modificada | Media (6.1) | 12% | — | Placeos Authentication | 30/9/2021 | 17/6/2026 | PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect. | |
| Modificada | Media (6.1) | 0.97% | — | Simplesamlphp Authentication Project Simplesamlphp Authentication | 9/9/2021 | 17/6/2026 | The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simplesamlphp-authentication.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.0. | |
| Modificada | Media (4.9) | 0.99% | — | IBM Sterling External Authentication ServerIBM Sterling Secure Proxy | 30/8/2021 | 17/6/2026 | IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 201160. | |
| Modificada | Alta (7.5) | 0.92% | — | IBM Sterling External Authentication ServerIBM Sterling Secure Proxy | 30/8/2021 | 17/6/2026 | IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100. |