Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2631▼ 309 respecto a la semana anterior
Críticas / altas1352▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.43% | — | Russellhaering Gosaml2AICasbin CasdoorAI | 28/5/2026 | 17/6/2026 | Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning that time bounds are computed by the… | |
| Analizada | Crítica (9.8) | 0.38% | — | Gosaliajainam Online-movie-booking | 2/1/2026 | 17/6/2026 | SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive information. | |
| Modificada | Media (5.3) | 0.96% | — | Gosaml2 Project Gosaml2 | 3/3/2023 | 17/6/2026 | gosaml2 is a Pure Go implementation of SAML 2.0. SAML Service Providers using this library for SAML authentication support are likely susceptible to Denial of Service attacks. A bug in this library enables attackers to craft a `deflate`-compressed request which will consume significantly more memory during processing… | |
| Modificada | Alta (7.5) | 1.7% | — | Gosaml2 Project Gosaml2 | 30/4/2021 | 17/6/2026 | This affects all versions <0.7.0 of package github.com/russellhaering/gosaml2. There is a crash on nil-pointer dereference caused by sending malformed XML signatures. | |
| Modificada | Media (6.5) | 1.2% | — | Gosa Project GosaDebian Linux | 31/12/2019 | 17/6/2026 | The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the web server) via a crafted cookie value, because unserialize is used to restore filter settings from… | |
| Modificada | Crítica (9.8) | 1.7% | — | Gonicus GosaDebian Linux | 15/8/2019 | 17/6/2026 | Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided. | |
| Modificada | Media (6.1) | 46% | — | Debian LinuxGonicus Gosa | 26/6/2018 | 17/6/2026 | GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary web script or HTML. This attack appear to be exploitable via the victim must open a specially… | |
| Modificada | Crítica (9.8) | 2.4% | — | Gosa Project Gosa Plugin | 13/2/2017 | 17/6/2026 | The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password. | |
| Modificada | Media (6.1) | 1.2% | — | Gosa Project Gosa | 13/2/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index.php in GOsa allows remote attackers to inject arbitrary web script or HTML via the username. | |
| Modificada | Media (5.4) | 0.27% | — | Santiagosarceda Elforro.com | 23/9/2014 | 17/6/2026 | The ElForro.com (aka com.tapatalk.elforrocom) application 2.4.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.4% | — | A-enterprise Gosamba | 1/11/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) HTML_oben.php, (2) inc_freigabe.php, (3) inc_freigabe1.php, or (4) inc_freigabe3.php in include/; (5) inc_group.php; (6) inc_manager.php; (7)… |