Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.33% | — | Apereo Central Authentication ServiceAI | 27/10/2025 | 17/6/2026 | A vulnerability was detected in Zytec Dalian Zhuoyun Technology Central Authentication Service up to 20251009. This vulnerability affects the function _empty of the file /index.php/auth/widget. Performing manipulation of the argument get.layer/get.widget/get.action results in code injection. The attack is possible to… | |
| Aplazada | Media (5.5) | 0.43% | — | Apereo Central Authentication ServiceAI | 5/10/2025 | 17/6/2026 | A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vulnerability is an unknown functionality of the file /index.php/auth/Ops/git of the component HTTP Header Handler. The manipulation of the argument Authorization leads to use of hard-coded password.… | |
| Analizada | Media (5.3) | 0.64% | — | Apereo Central Authentication Service | 27/4/2025 | 17/6/2026 | A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\core\cas-server-core-configuration-metadata-repository\src\main\java\org\apereo\cas\metadata\rest\CasConfigurationMetadataServerController.java. The manipulation of the… | |
| Analizada | Media (5.1) | 0.62% | — | Apereo Central Authentication Service | 27/4/2025 | 17/6/2026 | A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredServicesMultiActionController.java. The manipulation of the… | |
| Analizada | Baja (2.3) | 0.48% | — | Apereo Central Authentication Service | 27/4/2025 | 17/6/2026 | A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSimpleFormController.java of the component Groovy Code Handler.… | |
| Analizada | Media (5.3) | 0.62% | — | Apereo Central Authentication Service | 14/11/2024 | 17/6/2026 | A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (6.3) | 0.75% | — | Apereo Central Authentication Service | 14/11/2024 | 17/6/2026 | A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be… | |
| Analizada | Media (5.3) | 0.36% | — | Apereo Central Authentication Service | 14/11/2024 | 17/6/2026 | A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Crítica (9.1) | 1.8% | — | Apereo Central Authentication Service | 23/5/2024 | 17/6/2026 | The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack | |
| Modificada | Crítica (9.8) | 0.94% | — | Apereo Central Authentication Service | 9/11/2023 | 17/6/2026 | Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the… | |
| Modificada | Alta (7.5) | 0.50% | — | Apereo Central Authentication Service | 27/6/2023 | 17/6/2026 | Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake or a special HTTP header, such as “ssl_client_cert”. When checking the validity of the provided… | |
| Modificada | Media (6.1) | 8.2% | — | Apereo Central Authentication Service | 7/12/2021 | 17/6/2026 | Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints. | |
| Modificada | Alta (7.5) | 1.2% | — | Apereo Central Authentication Service | 16/10/2020 | 17/6/2026 | Apereo CAS 5.3.x before 5.3.16, 6.x before 6.1.7.2, 6.2.x before 6.2.4, and 6.3.x before 6.3.0-RC4 mishandles secret keys with Google Authenticator for multifactor authentication. | |
| Modificada | Alta (8.1) | 1.8% | — | Apereo Central Authentication Service | 23/9/2019 | 17/6/2026 | Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong. | |
| Modificada | Alta (7.5) | 2.8% | — | Apereo Central Authentication Service | 10/2/2015 | 17/6/2026 | Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication. |