Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

290 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.0%—Jenkins Keycloak Authentication26/1/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows attackers to trick users into logging in to the attacker's account.
ModificadaCrítica (9.8)1.2%—Jenkins Keycloak Authentication26/1/202317/6/2026
Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.
ModificadaAlta (8.8)1.2%—Jenkins Openid Connect Authentication26/1/202317/6/2026
Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login.
ModificadaMedia (6.1)0.41%—Moodle Saml Authentication12/1/202317/6/2026
Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
ModificadaMedia (6.3)0.50%—Microfocus Netiq Advanced Authentication28/11/202217/6/2026
This update resolves a multi-factor authentication bypass attack
ModificadaAlta (8.8)0.29%—Miniorange Wordpress Rest API Authentication18/11/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.
ModificadaBaja (3.3)0.18%—Intel Wlan Authentication AND Privacy Infrastructure11/11/202217/6/2026
Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaCrítica (9.8)2.1%—Osuosl Twisted VNC Authentication Proxy14/9/202217/6/2026
OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerability that could allow a malicious actor to gain unauthorized access to a VNC session or to disconnect a legitimate user from a VNC session. A remote attacker with network access…
ModificadaCrítica (9.8)1.3%—KB Login Authentication Script Project KB Login Authentication Script13/7/202217/6/2026
A vulnerability was found in KB Login Authentication Script 1.1 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the…
ModificadaMedia (6.7)1.0%—Thalesgroup Safenet Authentication Client24/6/202217/6/2026
Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, to overwrite arbitrary files, and potentially achieve arbitrary command execution with high privileges.
ModificadaMedia (5.3)0.88%—IBM Secure External Authentication ServerIBM Sterling Secure Proxy17/5/202217/6/2026
IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associated with the host due to improper validation of certificates. IBM X-Force ID: 201104.
ModificadaMedia (6.5)1.7%—Lmsdoctor 2 Factor Authentication10/5/202217/6/2026
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.
ModificadaAlta (7.5)2.3%—Lmsdoctor 2 Factor Authentication10/5/20229/7/2026
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.
ModificadaMedia (6.5)1.0%—Jenkins Gitlab Authentication15/3/202217/6/2026
Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
ModificadaMedia (4.4)0.17%—Citrix Federated Authentication Service10/3/202217/6/2026
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if…
ModificadaMedia (4.3)1.0%—IBM Sterling External Authentication Server24/2/202217/6/2026
IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which could be used for an attack. IBM X-Force ID: 220144.
ModificadaAlta (7.5)2.0%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy23/2/202217/6/2026
IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395.
ModificadaMedia (6.5)0.58%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy23/2/202217/6/2026
IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty based GUI in the Secure Zone not properly validating the sizes of the form content and/or HTTP headers submitted. A local attacker positioned inside the Secure Zone…
ModificadaMedia (5.4)0.72%—Jenkins Gitlab Authentication15/2/202217/6/2026
Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after logging in.
ModificadaAlta (7.8)0.32%—Thalesgroup Safenet Authentication Service Remote Desktop Gateway19/1/202217/6/2026
A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed.
ModificadaMedia (6.1)8.2%—Apereo Central Authentication Service7/12/202117/6/2026
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
ModificadaMedia (6.1)12%—Placeos Authentication30/9/202117/6/2026
PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.
ModificadaMedia (6.1)0.97%—Simplesamlphp Authentication Project Simplesamlphp Authentication9/9/202117/6/2026
The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simplesamlphp-authentication.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.0.
ModificadaMedia (4.9)0.99%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy30/8/202117/6/2026
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 201160.
ModificadaAlta (7.5)0.92%—IBM Sterling External Authentication ServerIBM Sterling Secure Proxy30/8/202117/6/2026
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100.