Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4) | 0.24% | — | Opensaml C++AI | 28/3/2025 | 17/6/2026 | The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures). | |
| Modificada | Media (5.9) | 0.84% | — | Shibboleth Identity ProviderShibboleth Opensaml Java | 4/4/2019 | 17/6/2026 | The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle… | |
| Modificada | Alta (8.1) | 1.4% | — | Shibboleth OpensamlDebian Linux | 16/11/2017 | 17/6/2026 | The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other… | |
| Modificada | Media (4.3) | 1.3% | — | Shibboleth Identity ProviderShibboleth Opensaml Java | 8/7/2015 | 17/6/2026 | The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor. | |
| Modificada | Media (5) | 2.8% | — | Internet2 OpensamlShibboleth Opensaml | 14/2/2014 | 17/6/2026 | The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration. | |
| Modificada | Media (5.8) | 2.3% | — | Shibboleth OpensamlShibboleth-identity-provider | 2/9/2011 | 16/6/2026 | Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack." | |
| Modificada | Alta (9.3) | 4.1% | — | Internet2 Shibboleth-spInternet2 OpensamlInternet2 Xmltooling | 29/9/2009 | 16/6/2026 | Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a… | |
| Modificada | Alta (7.5) | 1.5% | — | Internet2 OpensamlInternet2 XmltoolingInternet2 Shibboleth-sp | 29/9/2009 | 16/6/2026 | OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose,… |