Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2533▼ 405 respecto a la semana anterior
Críticas / altas1319▲ 38 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.23%—Onelogin Ruby-saml9/12/202517/6/2026
The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for document transformation, which allows an attacker to execute a Signature Wrapping attack. When…
AnalizadaCrítica (9.3)0.39%—Onelogin Ruby-saml9/12/202517/6/2026
The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for CVE-2025-25292. ReXML and Nokogiri parse XML differently, generating entirely different document structures from…
AplazadaAlta (7.7)0.32%—OneloginAI14/9/202517/6/2026
In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),
AplazadaMedia (6.9)0.40%—Onelogin Ruby-samlAI30/7/202517/6/2026
The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to…
AplazadaMedia (4)0.24%—Oneidentity OneloginAI19/7/202517/6/2026
In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.
AplazadaMedia (5)0.16%—Oneidentity Onelogin Active Directory ConnectorAI2/7/202517/6/2026
In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.
AplazadaCrítica (9)0.53%—Onelogin AD ConnectorAI1/7/202517/6/2026
A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-production) without validating bucket ownership. An attacker who registers this unclaimed bucket can begin receiving log files from other OneLogin tenants. These logs may contain…
AplazadaCrítica (10)0.61%—Onelogin AD ConnectorAI1/7/202517/6/2026
A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure of a tenant’s SSO JWT signing key via the /api/adc/v4/configuration endpoint. An attacker in possession of the signing key can craft valid JWT tokens impersonating arbitrary users within a OneLogin…
AplazadaMedia (5.7)0.16%—Onelogin AD ConnectorAI1/7/202517/6/2026
An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which may be retrievable from host registry keys or improperly secured logs—can retrieve a plaintext response disclosing…
ModificadaAlta (7.7)1.5%—Omniauth SamlOnelogin Ruby-saml12/3/202517/6/2026
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to…
ModificadaCrítica (9.3)65%—Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid12/3/202517/6/2026
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document…
ModificadaCrítica (9.3)21%—Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid12/3/202517/6/2026
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document…
ModificadaCrítica (9.8)11%—Onelogin Ruby-samlOmniauth SamlGitlab10/9/202417/6/2026
The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with…
ModificadaCrítica (9.8)1.3%—Onelogin Ruby-saml27/5/202317/6/2026
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
ModificadaAlta (7.5)1.7%—Onelogin Saml SSO22/8/201917/6/2026
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
ModificadaCrítica (9.8)2.5%—Onelogin Ruby-saml17/4/201917/6/2026
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service…
ModificadaCrítica (9.8)4.7%—Onelogin Pythonsaml17/4/201917/6/2026
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service…
ModificadaAlta (7.5)1.2%—Onelogin Ruby-saml23/1/201717/6/2026
Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.