Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Sin puntuar | — | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to… | |
| Aplazada | Sin puntuar | — | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS.… | |
| Aplazada | Sin puntuar | — | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed. This issue affects Apache Directory LDAP API: from 2.1.0 before… | |
| Aplazada | Sin puntuar | — | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE. This issue affects Apache Directory LDAP API: from… | |
| Aplazada | Alta (7.3) | 0.18% | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue. | |
| Aplazada | Sin puntuar | 0.19% | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service. The client JVM OOMs (OutOfMemoryError… | |
| Aplazada | Crítica (9.2) | 0.37% | — | Openbsd LdapdAI | 30/9/2026 | 1/10/2026 | In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier… | |
| En análisis | Media (6.3) | 0.35% | — | RabbitmqAIRabbitmq Auth Backend LdapAI | 25/9/2026 | 28/9/2026 | RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2, and 4.3 maintenance lines but contains conflicting first-fixed versions for the 3.13, 4.0, and 4.1 lines. fill/2 substitutes ${username} into user_dn_pattern without RFC 4514 DN escaping, allowing a crafted username to… | |
| Aplazada | Media (6.5) | 0.40% | — | Lemonldap NG HandlerAI | 25/9/2026 | 26/9/2026 | Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost's locationRules regular expressions against REQUEST_URI, the raw request line,… | |
| Aplazada | Crítica (9.1) | 0.39% | — | Lemonldap-ng Lemonldap NG PortalAI | 24/9/2026 | 26/9/2026 | Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaDataOptionsRequirePKCE set to 2, the authorization endpoint issues a code even when… | |
| Aplazada | Crítica (9.1) | 0.37% | — | Lemonldap-ng Lemonldap NG PortalAI | 24/9/2026 | 25/9/2026 | Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndPointAuthenticationCredentials() skips the secret comparison… | |
| Pendiente de análisis | Alta (7.8) | 0.20% | — | Auth0 AD Ldap ConnectorAI | 8/9/2026 | 10/9/2026 | The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account. | |
| Pendiente de análisis | Crítica (9) | 0.40% | — | Auth0 AD Ldap ConnectorAI | 8/9/2026 | 10/9/2026 | The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the… | |
| Pendiente de análisis | Media (6.7) | 0.18% | — | Auth0 AD Ldap ConnectorAI | 8/9/2026 | 10/9/2026 | The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to access the panel's management endpoints without credentials. Through these endpoints,… | |
| Aplazada | Crítica (9.9) | 0.55% | — | Eclipse AeriosAIKeycloakAIPostgresqlAIOpenldapAI | 8/9/2026 | 9/9/2026 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak service and its PostgreSQL backing database… | |
| Pendiente de análisis | Media (4.3) | 0.25% | — | Jenkins Ldap PluginAI | 2/9/2026 | 3/9/2026 | Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL. | |
| Analizada | Media (5.3) | 0.33% | — | Miniorange Ldap / Active Directory Integration | 2/9/2026 | 16/9/2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1. | |
| Aplazada | Media (6.3) | 0.58% | — | Erlang OTPAIErlang EldapAI | 1/9/2026 | 8/9/2026 | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits. eldap:parse_port/2 passes the port substring straight to list_to_integer/1 with no… | |
| Aplazada | Media (5.3) | 0.23% | — | Newpath WildapricotpressAI | 21/8/2026 | 26/8/2026 | The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only. | |
| Pendiente de análisis | Media (5) | 0.29% | — | Splunk AD LdapAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in plaintext. For more information see Run an… | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Splunk SoarAISplunk AD LdapAI | 19/8/2026 | 20/8/2026 | In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operations through the app. For more information see Run an action in Splunk SOAR… | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | Splunk Soar AD LdapAI | 19/8/2026 | 20/8/2026 | In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could inject crafted input into an Active Directory query to enumerate Active Directory objects, including accounts, groups, and organizational units, read sensitive attributes from arbitrary directory… | |
| Aplazada | Crítica (9.8) | 0.82% | — | Lemonldap NG PortalAI | 16/8/2026 | 26/8/2026 | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends. Before redirecting to the identity provider, extractFormInfo() creates the state… | |
| Aplazada | Baja (2.1) | 0.45% | — | Lemonldap-ngAI | 21/6/2026 | 22/6/2026 | A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open redirect. The attack is possible to be carried… | |
| Analizada | Alta (7.5) | 0.49% | — | Lldap | 15/6/2026 | 17/6/2026 | An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a crafted refresh-token header. |