Vulnerabilities
Summary — last 7 days
New vulnerabilities2,747▼ 495 vs. last week
Critical / high1,308▼ 202 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
5 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.3) | 0.42% | — | Openvpn Auth LdapAI | 6/27/2024 | 6/17/2026 | Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-auth-ldap (aka the Three Rings Auth-LDAP plugin for OpenVPN) 2.0.4 allows attackers with a valid LDAP username and who can control the challenge/response password field to pass a string with more than 14 colons into this field and cause a… | |
| Modified | Critical (9.8) | 0.85% | — | Ttrrs-auth-ldap Project Ttrrs-auth-ldap | 1/7/2023 | 6/17/2026 | A vulnerability, which was classified as problematic, has been found in hydrian TTRSS-Auth-LDAP. Affected by this issue is some unknown functionality of the component Username Handler. The manipulation leads to ldap injection. Upgrading to version 2.0b1 is able to address this issue. The patch is identified as… | |
| Modified | Critical (9.8) | 1.6% | — | Prosody MOD Auth LdapProsody MOD Auth Ldap2Debian Linux | 1/28/2020 | 6/17/2026 | The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin. | |
| Modified | High (7.5) | 5.4% | — | Dave Carrigan Auth Ldap | 1/9/2006 | 6/16/2026 | Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username. | |
| Modified | High (7.5) | 2.9% | — | C-note Squid Auth LdapPadl Software NSS LdapPadl Software PAM Ldap | 8/12/2002 | 6/16/2026 | Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages. |