Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

231 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaSin puntuar——Apache Directory Ldap APIAI2/10/20262/10/2026
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to…
AplazadaSin puntuar——Apache Directory Ldap APIAI2/10/20262/10/2026
Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS.…
AplazadaSin puntuar——Apache Directory Ldap APIAI2/10/20262/10/2026
Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed. This issue affects Apache Directory LDAP API: from 2.1.0 before…
AplazadaSin puntuar——Apache Directory Ldap APIAI2/10/20262/10/2026
Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE. This issue affects Apache Directory LDAP API: from…
AplazadaAlta (7.3)0.18%—Apache Directory Ldap APIAI2/10/20262/10/2026
Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue.
AplazadaSin puntuar0.19%—Apache Directory Ldap APIAI2/10/20262/10/2026
Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service. The client JVM OOMs (OutOfMemoryError…
AplazadaCrítica (9.2)0.37%—Openbsd LdapdAI30/9/20261/10/2026
In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier…
En análisisMedia (6.3)0.35%—RabbitmqAIRabbitmq Auth Backend LdapAI25/9/202628/9/2026
RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2, and 4.3 maintenance lines but contains conflicting first-fixed versions for the 3.13, 4.0, and 4.1 lines. fill/2 substitutes ${username} into user_dn_pattern without RFC 4514 DN escaping, allowing a crafted username to…
AplazadaMedia (6.5)0.40%—Lemonldap NG HandlerAI25/9/202626/9/2026
Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost's locationRules regular expressions against REQUEST_URI, the raw request line,…
AplazadaCrítica (9.1)0.39%—Lemonldap-ng Lemonldap NG PortalAI24/9/202626/9/2026
Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaDataOptionsRequirePKCE set to 2, the authorization endpoint issues a code even when…
AplazadaCrítica (9.1)0.37%—Lemonldap-ng Lemonldap NG PortalAI24/9/202625/9/2026
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndPointAuthenticationCredentials() skips the secret comparison…
Pendiente de análisisAlta (7.8)0.20%—Auth0 AD Ldap ConnectorAI8/9/202610/9/2026
The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.
Pendiente de análisisCrítica (9)0.40%—Auth0 AD Ldap ConnectorAI8/9/202610/9/2026
The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the…
Pendiente de análisisMedia (6.7)0.18%—Auth0 AD Ldap ConnectorAI8/9/202610/9/2026
The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints,…
AplazadaCrítica (9.9)0.55%—Eclipse AeriosAIKeycloakAIPostgresqlAIOpenldapAI8/9/20269/9/2026
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak service and its PostgreSQL backing database…
Pendiente de análisisMedia (4.3)0.25%—Jenkins Ldap PluginAI2/9/20263/9/2026
Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL.
AnalizadaMedia (5.3)0.33%—Miniorange Ldap / Active Directory Integration2/9/202616/9/2026
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.
AplazadaMedia (6.3)0.58%—Erlang OTPAIErlang EldapAI1/9/20268/9/2026
Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits. eldap:parse_port/2 passes the port substring straight to list_to_integer/1 with no…
AplazadaMedia (5.3)0.23%—Newpath WildapricotpressAI21/8/202626/8/2026
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.
Pendiente de análisisMedia (5)0.29%—Splunk AD LdapAISplunk SoarAI19/8/202620/8/2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in plaintext. For more information see Run an…
Pendiente de análisisMedia (4.3)0.29%—Splunk SoarAISplunk AD LdapAI19/8/202620/8/2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operations through the app. For more information see Run an action in Splunk SOAR…
Pendiente de análisisMedia (5.4)0.25%—Splunk Soar AD LdapAI19/8/202620/8/2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could inject crafted input into an Active Directory query to enumerate Active Directory objects, including accounts, groups, and organizational units, read sensitive attributes from arbitrary directory…
AplazadaCrítica (9.8)0.82%—Lemonldap NG PortalAI16/8/202626/8/2026
Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends. Before redirecting to the identity provider, extractFormInfo() creates the state…
AplazadaBaja (2.1)0.45%—Lemonldap-ngAI21/6/202622/6/2026
A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open redirect. The attack is possible to be carried…
AnalizadaAlta (7.5)0.49%—Lldap15/6/202617/6/2026
An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a crafted refresh-token header.