Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.5) | 0.26% | — | SEP SesamAIMicrosoft Active DirectoryAI | 12/9/2026 | 22/9/2026 | SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, which may allow multiple SEP sesam user accounts to be created for… | |
| Pendiente de análisis | Crítica (10) | 0.81% | — | Microsoft Azure Active Directory B2CAI | 3/9/2026 | 8/9/2026 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.3) | 0.33% | — | Miniorange Ldap / Active Directory Integration | 2/9/2026 | 16/9/2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | MS Graph FOR Active Directory APP FOR Splunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface.… | |
| Analizada | Crítica (9.9) | 0.82% | — | Microsoft Azure Active Directory | 7/8/2026 | 7/8/2026 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (8.8) | 0.80% | — | Samba Active Directory Domain ControllerAI | 30/7/2026 | 30/7/2026 | A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted… | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft Azure Active Directory | 14/7/2026 | 24/7/2026 | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.7% | — | Microsoft .net FrameworkMicrosoft Azure Active Directory | 14/7/2026 | 24/7/2026 | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. | |
| Analizada | Baja (3.7) | 0.33% | — | Jenkins Active Directory | 24/6/2026 | 26/6/2026 | Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to authenticate as a matching user whose… | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure Active Directory | 19/6/2026 | 24/6/2026 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.6) | 0.43% | — | Jenkins Active Directory | 27/5/2026 | 17/6/2026 | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. | |
| Analizada | Media (6.6) | 0.37% | — | Jenkins Active Directory | 27/5/2026 | 17/6/2026 | Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default. | |
| Analizada | Alta (8.6) | 0.14% | — | Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+11 | 25/5/2026 | 17/8/2026 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.… | |
| Aplazada | Alta (8.4) | 0.20% | — | Microsoft Active DirectoryAI | 31/10/2025 | 17/6/2026 | When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise confidentiality. | |
| Aplazada | Alta (8.8) | 0.80% | — | System Security Services Daemon SssdAIMicrosoft Active DirectoryAIMIT KerberosAI | 9/10/2025 | 31/8/2026 | A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with… | |
| Aplazada | Media (5) | 0.16% | — | Oneidentity Onelogin Active Directory ConnectorAI | 2/7/2025 | 17/6/2026 | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812. | |
| Aplazada | Media (6.5) | 0.51% | — | Splunk Supporting Add-on FOR Active DirectoryAISplunk Sa-ldapsearchAI | 30/1/2025 | 17/6/2026 | In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Sonicwall Ssl-vpnAIMicrosoft Active DirectoryAI | 9/1/2025 | 17/6/2026 | SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling… | |
| Modificada | Media (6.8) | 0.42% | — | Microsoft Azure Active Directory | 13/2/2024 | 10/8/2026 | Microsoft Azure Active Directory B2C Spoofing Vulnerability | |
| Modificada | Media (5.4) | 0.46% | — | Miniorange Staff / Employee Business Directory FOR Active Directory | 16/1/2024 | 17/6/2026 | The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against… | |
| Modificada | Alta (7.5) | 26% | — | Miniorange Active Directory Integration / Ldap Integration | 16/10/2023 | 17/6/2026 | The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so. | |
| Modificada | Media (6.5) | 0.91% | — | Miniorange Active Directory Integration / Ldap Integration | 27/9/2023 | 17/6/2026 | The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the… | |
| Modificada | Media (4.9) | 0.91% | — | Miniorange Staff / Employee Business Directory FOR Active Directory | 27/9/2023 | 17/6/2026 | The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to… | |
| Modificada | Media (5.9) | 0.46% | — | Jenkins Active Directory | 12/7/2023 | 17/6/2026 | Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory… | |
| Modificada | Alta (7.5) | 0.53% | — | Miniorange Active Directory Integration / Ldap Integration | 29/6/2023 | 17/6/2026 | The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to… |