Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.39% | — | Lemonldap-ng Lemonldap NG PortalAI | 24/9/2026 | 26/9/2026 | Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaDataOptionsRequirePKCE set to 2, the authorization endpoint issues a code even when… | |
| Aplazada | Crítica (9.1) | 0.37% | — | Lemonldap-ng Lemonldap NG PortalAI | 24/9/2026 | 25/9/2026 | Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndPointAuthenticationCredentials() skips the secret comparison… | |
| Aplazada | Baja (2.1) | 0.45% | — | Lemonldap-ngAI | 21/6/2026 | 22/6/2026 | A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open redirect. The attack is possible to be carried… | |
| Modificada | Media (6.1) | 0.33% | — | Lemonldap-ng Lemonldap\ | 9/10/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters. | |
| Modificada | Media (4.3) | 0.75% | — | Lemonldap-ng Lemonldap\ | 29/9/2023 | 17/6/2026 | A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770. | |
| Modificada | Crítica (9.8) | 0.78% | — | Lemonldap-ng Lemonldap\ | 29/5/2023 | 17/6/2026 | In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to bypass a Require directive. | |
| Modificada | Media (5.9) | 0.73% | — | Lemonldap-ng Lemonldap\ | 16/4/2023 | 17/6/2026 | In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically. | |
| Modificada | Crítica (9.8) | 0.96% | — | Lemonldap-ng Lemonldap\ | 31/3/2023 | 17/6/2026 | An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny session creation after the store step does not deny an AuthBasic session. | |
| Modificada | Alta (8.1) | 0.42% | — | Lemonldap-ng Apache\Debian Linux | 27/1/2023 | 17/6/2026 | In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix. | |
| Modificada | Alta (8.1) | 0.44% | — | Lemonldap-ng Apache\Debian Linux | 27/1/2023 | 17/6/2026 | In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix. | |
| Modificada | Crítica (9.8) | 1.2% | — | Lemonldap-ng Lemonldap\Debian Linux | 18/7/2022 | 17/6/2026 | An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in,… | |
| Modificada | Alta (7.5) | 0.77% | — | Lemonldap-ng Lemonldap\Debian Linux | 18/7/2022 | 17/6/2026 | In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. | |
| Modificada | Alta (8.8) | 1.8% | — | Lemonldap-ng Lemonldap\Debian Linux | 30/7/2021 | 17/6/2026 | An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users. | |
| Modificada | Crítica (9.8) | 2.4% | — | Lemonldap-ng Lemonldap\Debian Linux | 14/9/2020 | 17/6/2026 | An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package. | |
| Modificada | Crítica (9.8) | 2.5% | — | Lemonldap-ng Lemonldap\Debian Linux | 25/9/2019 | 17/6/2026 | OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no… | |
| Modificada | Alta (8.1) | 2.4% | — | Lemonldap-ng Lemonldap\Debian Linux | 28/6/2019 | 17/6/2026 | LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule. | |
| Modificada | Crítica (9.8) | 3.1% | — | Lemonldap-ng Lemonldap\Debian Linux | 22/5/2019 | 17/6/2026 | LemonLDAP::NG -2.0.3 has Incorrect Access Control. | |
| Modificada | Alta (7.5) | 1.6% | — | Lemonldap-ng Lemonldap\ | 1/1/2013 | 16/6/2026 | LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data. |