Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.3)0.26%—Internet2 GrouperAI30/9/202630/9/2026
In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.
AnalizadaMedia (4.9)0.27%—Internet2 Grouper19/9/202517/6/2026
In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.
AplazadaAlta (7.5)0.71%—Paxton Net2AI11/11/202417/6/2026
Insufficient validation performed on the REST API License file in Paxton Net2 before 6.07.14023.5015 (SR4) enables use of the REST API with an invalid License File. Attackers may be able to retrieve access-log data.
AplazadaCrítica (9.1)0.44%—Internet2 GrouperAIInternet2 Grouper FOR WEB ServicesAI29/6/202417/6/2026
Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1.
ModificadaCrítica (9.8)0.40%—Paxton-access Net219/12/202317/6/2026
When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or reverse engineer the source code to gain access to the root certificate password. Using the root certificate and password they could then create their own certificates…
ModificadaAlta (7.3)0.72%—Phoenixcontact AXL F BK PN TPS XC FirmwarePhoenixcontact AXL F BK PN TPS FirmwarePhoenixcontact AXL F BK EIP FirmwarePhoenixcontact AXL F BK EIP EF Firmware+1425/6/202117/6/2026
In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.
ModificadaMedia (5.5)0.39%—Net2 Project Net231/12/202017/6/2026
An issue was discovered in the net2 crate before 0.2.36 for Rust. It has false expectations about the std::net::SocketAddr memory representation.
ModificadaMedia (6.1)1.1%—Internet2 Grouper3/12/201817/6/2026
Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary web script or HTML via the code parameter.
ModificadaMedia (5)2.8%—Internet2 OpensamlShibboleth Opensaml14/2/201417/6/2026
The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.
ModificadaBaja (2.6)1.7%—Internet2 Identity ProviderInternet2 Service Provider6/11/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service Provider 1.3.x before 1.3.5 and 2.x before 2.3, in Internet2 Middleware Initiative Shibboleth allow remote attackers to inject arbitrary web script or HTML via URLs that are…
ModificadaAlta (9.3)4.1%—Internet2 Shibboleth-spInternet2 OpensamlInternet2 Xmltooling29/9/200916/6/2026
Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a…
ModificadaAlta (7.5)0.89%—Internet2 Shibboleth-sp29/9/200916/6/2026
Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly handle a '\0' character in the subject or subjectAltName fields of a certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted…
ModificadaAlta (7.5)1.5%—Internet2 OpensamlInternet2 XmltoolingInternet2 Shibboleth-sp29/9/200916/6/2026
OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose,…
ModificadaAlta (7.5)2.7%—Net2ftp28/11/200816/6/2026
Multiple directory traversal vulnerabilities in the (a) "Unzip archive" and (b) "Upload files and archives" functionality in net2ftp 0.96 stable and 0.97 beta allow remote attackers to create, read, or delete arbitrary files via a .. (dot dot) in a filename within a (1) TAR or (2) ZIP archive. NOTE: this can be…
ModificadaMedia (4.3)1.2%—Net2ftp10/10/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in net2ftp 0.93 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)3.9%—Net2ftp29/9/200616/6/2026
PHP remote file inclusion vulnerability in index.php in net2ftp, possibly 0.1 through 0.62, allows remote attackers to execute arbitrary PHP code via a URL in the application_rootdir parameter. NOTE: this issue has been disputed by a third party researcher, CVE, and the vendor. The vendor says "the variable is set in…
ModificadaMedia (5)1.6%—Fortinet2821/4/200616/6/2026
An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a "small synflood" to the SMTP port (TCP port 25), as demonstrated by a 10-microsecond wait between sending packets. NOTE: this issue has been disputed in followup posts that suggest that a protection feature…
ModificadaAlta (7.5)2.8%—Net2soft Flash FTP ServerAI31/12/200416/6/2026
Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot).