Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.23% | — | Onelogin Ruby-saml | 9/12/2025 | 17/6/2026 | The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for document transformation, which allows an attacker to execute a Signature Wrapping attack. When… | |
| Analizada | Crítica (9.3) | 0.39% | — | Onelogin Ruby-saml | 9/12/2025 | 17/6/2026 | The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for CVE-2025-25292. ReXML and Nokogiri parse XML differently, generating entirely different document structures from… | |
| Aplazada | Media (6.9) | 0.40% | — | Onelogin Ruby-samlAI | 30/7/2025 | 17/6/2026 | The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to… | |
| Modificada | Alta (7.7) | 1.5% | — | Omniauth SamlOnelogin Ruby-saml | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to… | |
| Modificada | Crítica (9.3) | 65% | — | Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document… | |
| Modificada | Crítica (9.3) | 21% | — | Omniauth SamlOnelogin Ruby-samlNetapp Storagegrid | 12/3/2025 | 17/6/2026 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document… | |
| Modificada | Crítica (9.8) | 11% | — | Onelogin Ruby-samlOmniauth SamlGitlab | 10/9/2024 | 17/6/2026 | The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with… | |
| Modificada | Crítica (9.8) | 1.3% | — | Onelogin Ruby-saml | 27/5/2023 | 17/6/2026 | xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used. | |
| Modificada | Crítica (9.8) | 2.5% | — | Onelogin Ruby-saml | 17/4/2019 | 17/6/2026 | OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service… | |
| Modificada | Alta (7.5) | 1.2% | — | Onelogin Ruby-saml | 23/1/2017 | 17/6/2026 | Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors. |