Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.59%—Altitude Authentication ServiceAIAltitude Communication ServerAI26/1/202617/6/2026
Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior…
AplazadaBaja (2.1)0.33%—Apereo Central Authentication ServiceAI27/10/202517/6/2026
A vulnerability was detected in Zytec Dalian Zhuoyun Technology Central Authentication Service up to 20251009. This vulnerability affects the function _empty of the file /index.php/auth/widget. Performing manipulation of the argument get.layer/get.widget/get.action results in code injection. The attack is possible to…
AplazadaAlta (8.3)0.45%—Element Matrix-authentication-serviceAI16/10/202517/6/2026
MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in matrix-authentication-service 0.20.0 through 1.4.0 allows an attacker with access to an authenticated MAS session to perform sensitive operations without…
AplazadaMedia (5.5)0.43%—Apereo Central Authentication ServiceAI5/10/202517/6/2026
A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vulnerability is an unknown functionality of the file /index.php/auth/Ops/git of the component HTTP Header Handler. The manipulation of the argument Authorization leads to use of hard-coded password.…
AnalizadaMedia (5.3)0.64%—Apereo Central Authentication Service27/4/202517/6/2026
A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\core\cas-server-core-configuration-metadata-repository\src\main\java\org\apereo\cas\metadata\rest\CasConfigurationMetadataServerController.java. The manipulation of the…
AnalizadaMedia (5.1)0.62%—Apereo Central Authentication Service27/4/202517/6/2026
A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredServicesMultiActionController.java. The manipulation of the…
AnalizadaBaja (2.3)0.48%—Apereo Central Authentication Service27/4/202517/6/2026
A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSimpleFormController.java of the component Groovy Code Handler.…
AplazadaMedia (6.9)0.40%—Centrify Authentication ServiceAI28/3/202517/6/2026
User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker to determine whether an email address is registered through specific error messages.
AnalizadaMedia (5.3)0.62%—Apereo Central Authentication Service14/11/202417/6/2026
A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.…
AnalizadaMedia (6.3)0.75%—Apereo Central Authentication Service14/11/202417/6/2026
A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be…
AnalizadaMedia (5.3)0.36%—Apereo Central Authentication Service14/11/202417/6/2026
A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may…
AnalizadaCrítica (9.1)1.8%—Apereo Central Authentication Service23/5/202417/6/2026
The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack
ModificadaCrítica (9.8)0.94%—Apereo Central Authentication Service9/11/202317/6/2026
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the…
ModificadaMedia (5.5)0.14%—Thalesgroup Safenet Authentication Service16/8/202317/6/2026
Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via local privilege escalation.
ModificadaAlta (7.5)0.50%—Apereo Central Authentication Service27/6/202317/6/2026
Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake or a special HTTP header, such as “ssl_client_cert”. When checking the validity of the provided…
ModificadaMedia (4.4)0.17%—Citrix Federated Authentication Service10/3/202217/6/2026
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if…
ModificadaAlta (7.8)0.32%—Thalesgroup Safenet Authentication Service Remote Desktop Gateway19/1/202217/6/2026
A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed.
ModificadaMedia (6.1)8.2%—Apereo Central Authentication Service7/12/202117/6/2026
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
ModificadaAlta (7.5)1.2%—Apereo Central Authentication Service16/10/202017/6/2026
Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication.
ModificadaAlta (7.8)1.2%—Centrify Authentication ServiceCentrify Privilege Elevation Service5/11/201917/6/2026
The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and 3.6.0 (19.6) does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows attackers to execute…
ModificadaAlta (8.1)1.8%—Apereo Central Authentication Service23/9/201917/6/2026
Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service FOR Citrix WEB Interface Agent2/3/201817/6/2026
SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service Windows Logon Agent2/3/201817/6/2026
SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7965.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service Windows Logon Agent2/3/201817/6/2026
SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7966.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service FOR NPS Agent2/3/201817/6/2026
SafeNet Authentication Service for NPS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.