Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Phpldapadmin Project PhpldapadminDebian Linux | 26/11/2019 | 16/6/2026 | A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via specially-crafted request. | |
| Modificada | Media (5.5) | 0.28% | — | Net-ldap Project Net-ldapDebian Linux | 21/11/2019 | 17/6/2026 | The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords. | |
| Modificada | Media (5.5) | 0.34% | — | Ldap GIT Backup Project Ldap GIT BackupDebian Linux | 7/11/2019 | 16/6/2026 | ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions. | |
| Modificada | Alta (7.5) | 0.89% | — | Jenkins Ldap Email | 1/10/2019 | 17/6/2026 | Jenkins LDAP Email Plugin transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. | |
| Modificada | Crítica (9.8) | 2.5% | — | Lemonldap-ng Lemonldap\Debian Linux | 25/9/2019 | 17/6/2026 | OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no… | |
| Modificada | Alta (7.5) | 5.0% | — | OpenldapCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+5 | 26/7/2019 | 17/6/2026 | An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL… | |
| Modificada | Media (4.9) | 3.4% | — | OpenldapCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+5 | 26/7/2019 | 17/6/2026 | An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from… | |
| Modificada | Alta (8.1) | 2.4% | — | Lemonldap-ng Lemonldap\Debian Linux | 28/6/2019 | 17/6/2026 | LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule. | |
| Modificada | Crítica (9.8) | 3.1% | — | Lemonldap-ng Lemonldap\Debian Linux | 22/5/2019 | 17/6/2026 | LemonLDAP::NG -2.0.3 has Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 3.3% | — | Icecoldapps Servers Ultimate | 5/10/2018 | 17/6/2026 | Ice Cold Apps Servers Ultimate 6.0.2(12) does not require authentication for TELNET, SSH, or FTP, which allows remote attackers to execute arbitrary code by uploading PHP scripts. | |
| Modificada | Crítica (9.8) | 5.2% | — | Apache Directory Ldap API | 10/7/2018 | 17/6/2026 | In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this… | |
| Modificada | Crítica (9.8) | 1.8% | — | Phpldapadmin Project Phpldapadmin | 22/6/2018 | 17/6/2026 | phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel. | |
| Modificada | Crítica (9.8) | 2.8% | — | Ltb-project Ldap Tool BOX Self Service Password | 14/6/2018 | 17/6/2026 | LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string. | |
| Modificada | Alta (8.1) | 2.4% | — | Horde Ldap | 10/4/2018 | 17/6/2026 | The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN. | |
| Modificada | Alta (8.8) | 1.3% | — | Debian LinuxLdap-account-manager Ldap Account Manager | 27/3/2018 | 17/6/2026 | Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging. | |
| Modificada | Media (6.1) | 1.5% | — | Debian LinuxLdap-account-manager Ldap Account Manager | 27/3/2018 | 17/6/2026 | Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI. | |
| Modificada | Crítica (9.8) | 4.7% | — | Pingidentity Ldapsdk | 16/3/2018 | 17/6/2026 | UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue was reported and fixed contains an Incorrect Access Control vulnerability in process function in SimpleBindRequest class doesn't check for empty password when running… | |
| Modificada | Media (5.9) | 0.87% | — | LdaptiveLdaptive Vt-ldap | 8/1/2018 | 17/6/2026 | DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Alta (7.5) | 7.0% | — | OpenldapOpensuse LeapOracle Blockchain PlatformMcafee Policy Auditor | 18/12/2017 | 17/6/2026 | contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation. | |
| Modificada | Media (5.9) | 1.3% | — | Net-ldap Project Net-ldap | 17/12/2017 | 17/6/2026 | The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation. | |
| Modificada | Alta (8.1) | 2.6% | — | Pivotal Software Spring-ldapDebian Linux | 27/11/2017 | 17/6/2026 | In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication… | |
| Modificada | Alta (8.1) | 1.7% | — | Go-ldap Project Ldap | 20/9/2017 | 17/6/2026 | In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This issue affects an application using this package if these conditions are met: (1) it relies only on the return error of the Bind function call to determine whether a user is authorized (i.e., a nil… | |
| Modificada | Alta (7.5) | 5.1% | — | Apache Directory Ldap API | 7/9/2017 | 17/6/2026 | Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.1% | — | Ldapauth-fork Project Ldapauth-fork | 6/9/2017 | 17/6/2026 | ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection attacks via a crafted username. | |
| Modificada | Media (4.7) | 0.35% | — | OpenldapOracle Blockchain Platform | 5/9/2017 | 17/6/2026 | slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by… |