Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | Simplesamlphp | 1/9/2017 | 17/6/2026 | The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation. | |
| Modificada | Media (5.9) | 1.3% | — | Simplesamlphp | 29/8/2017 | 17/6/2026 | The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset. | |
| Modificada | Alta (7.5) | 5.0% | — | Pysaml2 Project Pysaml2Debian Linux | 24/3/2017 | 17/6/2026 | XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response. | |
| Modificada | Crítica (9) | 2.6% | — | Pysaml2 Project Pysaml2 | 3/3/2017 | 17/6/2026 | PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response. | |
| Modificada | Media (6.3) | 1.2% | — | SimplesamlphpDebian Linux | 17/2/2017 | 17/6/2026 | The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean. | |
| Modificada | Crítica (9.1) | 2.4% | — | SimplesamlphpSimplesamlphp Saml2 | 17/2/2017 | 17/6/2026 | The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of… | |
| Modificada | Media (5.3) | 1.3% | — | Simplesamlphp | 7/2/2017 | 17/6/2026 | The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Onelogin Ruby-saml | 23/1/2017 | 17/6/2026 | Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Shibboleth Identity ProviderShibboleth Opensaml Java | 8/7/2015 | 17/6/2026 | The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor. | |
| Modificada | Media (5) | 2.8% | — | Internet2 OpensamlShibboleth Opensaml | 14/2/2014 | 17/6/2026 | The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration. | |
| Modificada | Baja (2.1) | 1.5% | — | HP Icewall Smart Device OptionHP Icewall SSO AgentHP Icewall SSO Saml2 OptionHP Icewall File Manager+3 | 23/9/2013 | 16/6/2026 | Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, IceWall SSO SAML2 Agent Option 8.0, IceWall SSO JAVA Agent Library 8.0 through 10.0, IceWall Federation Agent 3.0, and IceWall File Manager 3.0 through SP4 allows remote… | |
| Modificada | Media (4.3) | 1.3% | — | Simplesamlphp | 24/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the link_href parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Simplesamlphp | 24/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter. | |
| Modificada | Media (5.8) | 2.3% | — | Shibboleth OpensamlShibboleth-identity-provider | 2/9/2011 | 16/6/2026 | Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack." | |
| Modificada | Alta (9.3) | 4.1% | — | Internet2 Shibboleth-spInternet2 OpensamlInternet2 Xmltooling | 29/9/2009 | 16/6/2026 | Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a… | |
| Modificada | Alta (7.5) | 1.5% | — | Internet2 OpensamlInternet2 XmltoolingInternet2 Shibboleth-sp | 29/9/2009 | 16/6/2026 | OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose,… |