Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.56% | — | EMC RSA Authentication ManagerRSA Authentication Manager | 3/12/2019 | 17/6/2026 | RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a… | |
| Modificada | Alta (7.5) | 1.3% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 26/11/2019 | 17/6/2026 | Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well. | |
| Modificada | Alta (7.8) | 1.2% | — | Centrify Authentication ServiceCentrify Privilege Elevation Service | 5/11/2019 | 17/6/2026 | The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and 3.6.0 (19.6) does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows attackers to execute… | |
| Modificada | Alta (8.8) | 1.7% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticated users to execute arbitrary SQL commands via the source or subString parameter. | |
| Modificada | Media (6.1) | 1.7% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/groups.jsp. The groupName parameter is vulnerable: the reflected cross-site scripting occurs immediately after the group is… | |
| Modificada | Media (6.1) | 1.7% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML that is triggered when Logs.jsp is visited. The rendered_message column is retrieved and displayed, unsanitized, on Logs.jsp. A remote attack can populate… | |
| Modificada | Media (6.1) | 1.7% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allows remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/userPreregistration.jsp. The preRegistrationData parameter is vulnerable: a reflected cross-site scripting occurs immediately… | |
| Modificada | Alta (8.8) | 2.1% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain parameters are used, unsanitized, in a SQL query constructed in the buildSearchWhereClause function. | |
| Modificada | Alta (8.8) | 1.3% | — | Cloudfoundry User Account AND Authentication | 26/9/2019 | 17/6/2026 | CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, ultimately allowing the malicious user to gain control of UAA scopes they should… | |
| Modificada | Alta (8.1) | 1.8% | — | Apereo Central Authentication Service | 23/9/2019 | 17/6/2026 | Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong. | |
| Modificada | Media (6.1) | 0.99% | — | Simbahosting Two-factor-authentication | 28/8/2019 | 17/6/2026 | The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area. | |
| Modificada | Crítica (9.8) | 1.5% | — | Xm-online Xm^online 2 User Account AND Authentication Server | 26/8/2019 | 17/6/2026 | XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key. | |
| Modificada | Alta (8.8) | 3.8% | — | Microsoft Active Directory Authentication LibraryMicrosoft Nuget | 14/8/2019 | 17/6/2026 | An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in the way the library caches tokens. This vulnerability allows an authenticated attacker to perform actions in context of another user. The authenticated attacker can exploit this vulneraiblity by… | |
| Modificada | Media (6.1) | 0.80% | — | Cloudfoundry User Account AND Authentication | 9/8/2019 | 17/6/2026 | Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that contains a SCIM filter that contains malicious JavaScript, which older browsers may execute. | |
| Modificada | Media (5.9) | 0.82% | — | Microfocus Netiq Advanced Authentication | 10/7/2019 | 17/6/2026 | A potential Man in the Middle attack (MITM) was found in NetIQ Advanced Authentication Framework versions prior to 6.0. | |
| Modificada | Alta (8.8) | 2.8% | — | Risk AuthenticationStrong Authentication | 28/5/2019 | 17/6/2026 | A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x allows an authenticated attacker to gain additional privileges in some cases where an account has… | |
| Modificada | Media (4.3) | 2.3% | — | Risk AuthenticationStrong Authentication | 28/5/2019 | 17/6/2026 | A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x may allow a remote attacker to gain sensitive information in some cases. | |
| Modificada | Media (4.3) | 0.77% | — | Jenkins Pluggable Authentication Module | 21/5/2019 | 17/6/2026 | A missing permission check in Jenkins PAM Authentication Plugin 1.5 and earlier, except 1.4.1 in PamSecurityRealm.DescriptorImpl#doTest allowed users with Overall/Read permission to obtain limited information about the file /etc/shadow and the user Jenkins is running as. | |
| Modificada | Crítica (9.8) | 2.0% | — | THE University OF Cambridge WEB Authentication System Apache Authentication Agent | 13/5/2019 | 17/6/2026 | Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification field ("kid") of the IdP's HTTP response message ("WLS-Response") can be manipulated by an attacker. The "kid" field is not signed like the rest of the message, and manipulation is therefore trivial. The… | |
| Modificada | Alta (8.8) | 2.1% | — | Jenkins Github Authentication | 30/4/2019 | 17/6/2026 | Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF. | |
| Modificada | Alta (7.2) | 2.0% | — | EMC RSA Authentication ManagerRSA Authentication Manager | 13/3/2019 | 17/6/2026 | RSA Authentication Manager versions prior to 8.4 P1 contain an Insecure Credential Management Vulnerability. A malicious Operations Console administrator may be able to obtain the value of a domain password that another Operations Console administrator had set previously and use it for attacks. | |
| Modificada | Media (4.3) | 1.1% | — | Jenkins Openid Connect Authentication | 6/2/2019 | 17/6/2026 | An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlier in OicSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client… | |
| Modificada | Alta (7.8) | 0.42% | — | RSA Authentication Manager | 16/1/2019 | 17/6/2026 | The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with a crafted license that if used during the quick setup deployment of the initial RSA Authentication Manager system,… | |
| Modificada | Alta (8.8) | 1.4% | — | Simbahosting Two-factor-authentication | 19/12/2018 | 17/6/2026 | Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due to missing nonce validation. | |
| Modificada | Media (4.7) | 1.5% | — | RSA Authentication ManagerEMC RSA Authentication Manager | 28/9/2018 | 17/6/2026 | RSA Authentication Manager versions prior to 8.3 P3 contain a reflected cross-site scripting vulnerability in a Security Console page. A remote, unauthenticated malicious user, with the knowledge of a target user's anti-CSRF token, could potentially exploit this vulnerability by tricking a victim Security Console user… |