Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.40% | — | Lemonldap NG HandlerAI | 25/9/2026 | 26/9/2026 | Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost's locationRules regular expressions against REQUEST_URI, the raw request line,… | |
| Aplazada | Crítica (9.1) | 0.39% | — | Lemonldap-ng Lemonldap NG PortalAI | 24/9/2026 | 26/9/2026 | Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaDataOptionsRequirePKCE set to 2, the authorization endpoint issues a code even when… | |
| Aplazada | Crítica (9.1) | 0.37% | — | Lemonldap-ng Lemonldap NG PortalAI | 24/9/2026 | 25/9/2026 | Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndPointAuthenticationCredentials() skips the secret comparison… | |
| Aplazada | Crítica (9.8) | 0.82% | — | Lemonldap NG PortalAI | 16/8/2026 | 26/8/2026 | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends. Before redirecting to the identity provider, extractFormInfo() creates the state… | |
| Aplazada | Baja (2.1) | 0.45% | — | Lemonldap-ngAI | 21/6/2026 | 22/6/2026 | A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open redirect. The attack is possible to be carried… | |
| Aplazada | Alta (7.2) | 0.38% | — | Lemonldap NGAI | 16/1/2026 | 17/6/2026 | In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication. | |
| Aplazada | Alta (8.4) | 0.36% | — | Lemonsoft Wordpress ADD ONAI | 13/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lemonsoft WordPress add on allows Cross-Site Scripting (XSS).This issue affects WordPress add on: 2025.7.1. | |
| Analizada | Crítica (9.1) | 0.78% | — | Lemon8866 Streamvault | 27/12/2025 | 17/6/2026 | StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault application (SpiritApplication). The application allows administrators to configure yt-dlp arguments via the /admin/api/saveConfig endpoint without sufficient… | |
| Aplazada | Alta (8) | 1.2% | — | Lemonldap NGAI | 17/9/2025 | 17/6/2026 | In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server. | |
| Aplazada | Alta (8.7) | 1.2% | — | Lemon8866 StreamvaultAI | 1/9/2025 | 17/6/2026 | StreamVault is a multi-platform video parsing and downloading tool. Prior to version 250822, after logging into the StreamVault-system, an attacker can modify certain system parameters, construct malicious commands, execute command injection attacks against the system, and ultimately gain server privileges. Users of… | |
| Analizada | Baja (2.1) | 0.38% | — | Mossle Lemon | 25/8/2025 | 17/6/2026 | A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the component com.mossle.cms.web.CmsArticleController.uploadImage. This manipulation of the argument Upload causes unrestricted upload. The attack can be initiated remotely.… | |
| Analizada | Media (5.5) | 0.97% | — | Lemonos | 15/8/2025 | 17/6/2026 | A vulnerability was determined in LemonOS up to nightly-2024-07-12 on LemonOS. Affected by this issue is the function HTTPGet of the file /Applications/Steal/main.cpp of the component HTTP Client. The manipulation of the argument chunkSize leads to stack-based buffer overflow. The attack may be launched remotely. The… | |
| Aplazada | Alta (7.1) | 0.26% | — | Lemonadestudio Lemonade Social Networks Autoposter PinterestAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lemonadestudio Lemonade Social Networks Autoposter Pinterest lemonade-sna-pinterest-edition allows Reflected XSS.This issue affects Lemonade Social Networks Autoposter Pinterest: from n/a through <= 2.0. | |
| Aplazada | Media (5.4) | 0.60% | — | Mobilemonkey Wp-chatbot FOR MessengerAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in MobileMonkey WP-Chatbot for Messenger allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Chatbot for Messenger: from n/a through 4.7. | |
| Aplazada | Media (5.4) | 0.31% | — | Lemonldap NGAI | 18/11/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the "Upgrade session" plugin has been enabled by an admin | |
| Aplazada | Alta (8.8) | 0.49% | — | Lemonldap NGAI | 18/11/2024 | 17/6/2026 | An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value. | |
| Aplazada | Crítica (9.1) | 0.41% | — | Lemonldap NGAI | 10/11/2024 | 17/6/2026 | An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e., it does not verify access token validity. An attacker can use a expired access token from an OIDC client to access the OAuth2 handler The earliest affected version is 2.0.4. | |
| Modificada | Media (6.1) | 0.33% | — | Lemonldap-ng Lemonldap\ | 9/10/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters. | |
| Aplazada | Crítica (9.1) | 0.52% | — | Lemonldap NGAI | 9/10/2024 | 17/6/2026 | Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret). | |
| Modificada | Media (4.3) | 0.75% | — | Lemonldap-ng Lemonldap\ | 29/9/2023 | 17/6/2026 | A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770. | |
| Modificada | Crítica (9.8) | 0.78% | — | Lemonldap-ng Lemonldap\ | 29/5/2023 | 17/6/2026 | In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to bypass a Require directive. | |
| Modificada | Media (5.9) | 0.73% | — | Lemonldap-ng Lemonldap\ | 16/4/2023 | 17/6/2026 | In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically. | |
| Modificada | Crítica (9.8) | 0.96% | — | Lemonldap-ng Lemonldap\ | 31/3/2023 | 17/6/2026 | An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny session creation after the store step does not deny an AuthBasic session. | |
| Modificada | Alta (8.1) | 0.42% | — | Lemonldap-ng Apache\Debian Linux | 27/1/2023 | 17/6/2026 | In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix. | |
| Modificada | Alta (8.1) | 0.44% | — | Lemonldap-ng Apache\Debian Linux | 27/1/2023 | 17/6/2026 | In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix. |