Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2631▼ 309 respecto a la semana anterior
Críticas / altas1352▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.43%—Russellhaering Gosaml2AICasbin CasdoorAI28/5/202617/6/2026
Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning that time bounds are computed by the…
AnalizadaCrítica (9.8)0.38%—Gosaliajainam Online-movie-booking2/1/202617/6/2026
SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive information.
ModificadaMedia (5.3)0.96%—Gosaml2 Project Gosaml23/3/202317/6/2026
gosaml2 is a Pure Go implementation of SAML 2.0. SAML Service Providers using this library for SAML authentication support are likely susceptible to Denial of Service attacks. A bug in this library enables attackers to craft a `deflate`-compressed request which will consume significantly more memory during processing…
ModificadaAlta (7.5)1.7%—Gosaml2 Project Gosaml230/4/202117/6/2026
This affects all versions <0.7.0 of package github.com/russellhaering/gosaml2. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.
ModificadaMedia (6.5)1.2%—Gosa Project GosaDebian Linux31/12/201917/6/2026
The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the web server) via a crafted cookie value, because unserialize is used to restore filter settings from…
ModificadaCrítica (9.8)1.7%—Gonicus GosaDebian Linux15/8/201917/6/2026
Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.
ModificadaMedia (6.1)46%—Debian LinuxGonicus Gosa26/6/201817/6/2026
GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary web script or HTML. This attack appear to be exploitable via the victim must open a specially…
ModificadaCrítica (9.8)2.4%—Gosa Project Gosa Plugin13/2/201717/6/2026
The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.
ModificadaMedia (6.1)1.2%—Gosa Project Gosa13/2/201717/6/2026
Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index.php in GOsa allows remote attackers to inject arbitrary web script or HTML via the username.
ModificadaMedia (5.4)0.27%—Santiagosarceda Elforro.com23/9/201417/6/2026
The ElForro.com (aka com.tapatalk.elforrocom) application 2.4.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)2.4%—A-enterprise Gosamba1/11/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) HTML_oben.php, (2) inc_freigabe.php, (3) inc_freigabe1.php, or (4) inc_freigabe3.php in include/; (5) inc_group.php; (6) inc_manager.php; (7)…