Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.92% | — | IBM Sterling External Authentication ServerIBM Sterling Secure Proxy | 30/8/2021 | 17/6/2026 | IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095. | |
| Modificada | Media (6.1) | 0.71% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 11/8/2021 | 17/6/2026 | UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by social engineering leading to take over of victims’ accounts in certain cases along with redirection of UAA users to a malicious sites. | |
| Modificada | Alta (7.5) | 0.99% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 22/7/2021 | 17/6/2026 | In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server. | |
| Modificada | Media (5.4) | 0.83% | — | IBM Secure External Authentication ServerIBM Sterling Secure Proxy | 15/7/2021 | 17/6/2026 | IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201777. | |
| Modificada | Alta (7.5) | 2.9% | — | IBM Secure External Authentication ServerIBM Sterling Secure Proxy | 15/7/2021 | 17/6/2026 | IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. | |
| Modificada | Media (6.5) | 0.69% | — | Microfocus Netiq Advanced Authentication | 12/7/2021 | 17/6/2026 | Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1. | |
| Modificada | Alta (7.2) | 0.76% | — | Microfocus Netiq Advanced Authentication | 12/4/2021 | 17/6/2026 | Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue. | |
| Modificada | Alta (7.1) | 0.27% | — | DUO Authentication Proxy | 25/3/2021 | 17/6/2026 | The Duo Authentication Proxy installer prior to 5.2.1 did not properly validate file installation paths. This allows an attacker with local user privileges to coerce the installer to write to arbitrary privileged directories. If successful, an attacker can manipulate files used by Duo Authentication Proxy installer,… | |
| Modificada | Crítica (9.8) | 1.7% | — | Spnego Http Authentication Module Project Spnego Http Authentication Module | 8/3/2021 | 17/6/2026 | In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a malformed username. This affects users of spnego-http-auth-nginx-module that have enabled basic authentication. This is fixed in version 1.1.1 of… | |
| Modificada | Alta (7.5) | 1.2% | — | Apereo Central Authentication Service | 16/10/2020 | 17/6/2026 | Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication. | |
| Modificada | Alta (7.8) | 0.31% | — | Cisco DUO Authentication FOR Windows Logon AND RDP | 14/10/2020 | 17/6/2026 | The Windows Logon installer prior to 4.1.2 did not properly validate file installation paths. This allows an attacker with local user privileges to coerce the installer to write to arbitrary privileged directories. If successful, an attacker can manipulate files used by Windows Logon, cause Denial of Service (DoS) by… | |
| Modificada | Media (5.1) | 0.22% | — | Twilio Authy 2-factor Authentication | 10/9/2020 | 17/6/2026 | A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to potentially approve/deny an access request prior to unlocking the application with a PIN on older Android devices (effectively bypassing the PIN requirement). | |
| Modificada | Alta (8.4) | 0.39% | — | RSA Multifactor Authentication Agent | 31/7/2020 | 17/6/2026 | Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability. A local unauthenticated attacker could potentially exploit this vulnerability by using an alternate path to bypass authentication in order to gain full access to the system. | |
| Modificada | Alta (8.2) | 3.2% | — | IBM Sterling External Authentication ServerIBM Sterling Secure Proxy | 16/7/2020 | 17/6/2026 | IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or… | |
| Modificada | Alta (8.8) | 1.4% | — | Jenkins Gitlab Authentication | 15/7/2020 | 17/6/2026 | Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability. | |
| Modificada | Media (5.4) | 0.70% | — | Django Two-factor Authentication Project Django Two-factor Authentication | 10/7/2020 | 17/6/2026 | Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authentication code. This means… | |
| Modificada | Media (4.8) | 0.64% | — | EMC RSA Authentication Manager | 15/4/2020 | 17/6/2026 | RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the… | |
| Modificada | Media (4.8) | 0.67% | — | EMC RSA Authentication Manager | 26/3/2020 | 17/6/2026 | RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the… | |
| Modificada | Media (4.8) | 0.67% | — | EMC RSA Authentication Manager | 26/3/2020 | 17/6/2026 | RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the… | |
| Modificada | Alta (8.8) | 0.49% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 27/2/2020 | 17/6/2026 | In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers. | |
| Modificada | Alta (7.8) | 0.58% | — | IBM Sterling External Authentication Server | 11/2/2020 | 16/6/2026 | A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command, which could let a local malicious user execute arbitrary code. | |
| Modificada | Media (6.5) | 1.1% | — | EMC RSA Authentication Manager | 3/1/2020 | 17/6/2026 | RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by supplying specially crafted XML message. | |
| Modificada | Alta (7.5) | 0.83% | — | Http Authentication Library Project Http Authentication Library | 30/12/2019 | 17/6/2026 | The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used. | |
| Modificada | Media (6.5) | 4.6% | — | Microsoft Authentication Library | 10/12/2019 | 17/6/2026 | An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or later exists under specific conditions, aka 'Microsoft Authentication Library for Android Information Disclosure Vulnerability'. | |
| Modificada | Media (6.5) | 1.3% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 6/12/2019 | 17/6/2026 | Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters. |