Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2509▼ 448 respecto a la semana anterior
Críticas / altas1286▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 464 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.3)0.19%—Splunk SoarAIMicrosoft Azure AD GraphAI19/8/202620/8/2026
In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface. The information…
AplazadaAlta (8.2)0.20%—OpenprojectAIMicrosoft OnedriveAIMicrosoft SharepointAIMicrosoft Azure ADAI26/6/202629/6/2026
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key storage.<id>.httpx_access_token, repopulated continuously by an hourly cron and…
AnalizadaMedia (4.3)0.33%—Jenkins Azure AD29/4/202617/6/2026
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
AnalizadaAlta (8.1)0.29%—Microsoft Azure AD SSH Login Extension FOR Linux10/3/202617/6/2026
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.
AplazadaCrítica (9.8)0.73%—Miniorange ALL IN ONE Microsoft 365 Entra ID Azure AD SSO LoginAI3/3/202617/6/2026
The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators.
AplazadaMedia (6.4)0.27%—Miniorange Wordpress Office 365 Azure AD LoginAI23/5/202417/6/2026
The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaAlta (7.5)0.81%—Jenkins Azure AD6/9/202317/6/2026
Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing attackers to use statistical methods to obtain a valid nonce.
ModificadaAlta (8.8)1.0%—Jenkins Azure AD26/1/202317/6/2026
Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login.
ModificadaMedia (5.3)0.74%—Microsoft Azure AD POD Identity21/12/202217/6/2026
aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request made with backslash in the request (example:…
ModificadaMedia (6.1)0.97%—Wpo365 Wordpress + Azure AD / Microsoft Office 36519/11/202117/6/2026
The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper…
ModificadaAlta (8.8)0.68%—Jenkins Azure AD31/8/202117/6/2026
Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
ModificadaAlta (7.5)2.1%—Wpo365 Wordpress + Azure AD / Microsoft Office 3652/10/202017/6/2026
The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.
ModificadaMedia (5.3)0.92%—Jenkins Azure AD12/2/202017/6/2026
Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
ModificadaAlta (8.8)1.8%—Jenkins Azure AD30/4/201917/6/2026
Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration file on the Jenkins master where it could be viewed by users with access to the master file system.