Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.37% | — | Saml Single Sign ONAI | 20/9/2026 | 21/9/2026 | The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a… | |
| Pendiente de análisis | Alta (7.7) | 0.69% | — | Kong Saml PluginAI | 16/9/2026 | 18/9/2026 | A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned assertion and authenticate the user without verifying a valid… | |
| Aplazada | Crítica (9.8) | 0.63% | — | Frontegg Saml SSOAI | 12/9/2026 | 14/9/2026 | The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts. | |
| Aplazada | Crítica (9.1) | 0.31% | — | Passport Saml EncryptedAI | 10/9/2026 | 10/9/2026 | passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned assertion that gets accepted as the… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Passport-saml-encryptedAI | 10/9/2026 | 11/9/2026 | passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to… | |
| Aplazada | Crítica (9.8) | 0.31% | — | Mojox AuthenticationAINET Saml2AI | 6/9/2026 | 8/9/2026 | MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or anchors argument, then passes… | |
| Aplazada | Alta (8.8) | 0.28% | — | Saml Mendix 10 CompatibleAISaml Mendix 11 CompatibleAISaml Mendix 9.24 CompatibleAI | 3/9/2026 | 8/9/2026 | A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Jenkins SamlAIStaplerAI | 2/9/2026 | 3/9/2026 | Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user. | |
| Aplazada | Alta (7.5) | 0.41% | — | Miniorange Saml SSOAI | 29/8/2026 | 31/8/2026 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_saml_required_certificate option before… | |
| Pendiente de análisis | Media (6.9) | 0.26% | — | Pac4j-samlAI | 29/8/2026 | 10/9/2026 | pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest(). When an IdP sends no SessionIndex, a session can be destroyed based solely on the NameID, allowing an unauthenticated attacker to submit an unsigned LogoutRequest with a guessed… | |
| Aplazada | Crítica (10) | 0.60% | — | Miniorange Saml SSOAIMiniorange Saml SP Single Sign ON Login With AdfsAIMiniorange Saml SP Single Sign ON Saml SSO Login With Google AppsAIJoomlaAI | 25/8/2026 | 8/9/2026 | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the mo_saml_validate_signature() function performing a… | |
| Pendiente de análisis | Alta (7.6) | 0.22% | — | Dropbox SamlyAI | 20/8/2026 | 24/8/2026 | Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested. Samly.SPHandler.validate_authresp/3 in lib/samly/sp_handler.ex validates a SAML response for the SP-initiated flow by… | |
| Pendiente de análisis | Crítica (9.1) | 0.60% | — | Dropbox SamlyAI | 20/8/2026 | 24/8/2026 | Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esaml_sp:validate_assertion/2, whose default duplicate detector is a no-op. The /3… | |
| Aplazada | Alta (7.5) | 0.78% | — | Simplesamlphp Saml2AI | 19/8/2026 | 18/9/2026 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML signatures in specially crafted SAML messages. XPath evaluation can consume uncontrolled processing resources, allowing a remote… | |
| Aplazada | Alta (8.7) | 0.47% | — | Simplesamlphp Saml2AI | 19/8/2026 | 18/9/2026 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as cryptographically valid for the wrong identity provider. SOAPClient::addSSLValidator() attaches a… | |
| Aplazada | Alta (8.8) | 0.26% | — | Saml Single Sign ONAI | 19/8/2026 | 26/8/2026 | The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a… | |
| Aplazada | Alta (8.1) | 0.37% | — | Miniorange Saml SP Single Sign ONAI | 13/8/2026 | 14/8/2026 | Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions. | |
| Aplazada | Media (6.9) | 0.38% | — | AdmidioAILightsamlAI | 3/8/2026 | 9/9/2026 | Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers can inject arbitrary JavaScript through SAML Issuer elements or LightSaml library parameters to execute code in users'… | |
| Pendiente de análisis | Crítica (9.8) | 1.9% | — | Miniorange Saml Single Sign ONAI | 23/7/2026 | 24/7/2026 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return… | |
| Analizada | Alta (7.1) | 0.22% | — | Simplesamlphp | 17/7/2026 | 30/7/2026 | SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSAMLphp's SAML SP ACS path does not enforce the IdP selected for an SP-initiated login when unsigned Response/InResponseTo is combined with a signed assertion lacking… | |
| Aplazada | Crítica (9.8) | 1.5% | — | Miniorange Saml Single Sign ON SSOAI | 16/7/2026 | 7/8/2026 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the `SignatureMethod` Algorithm attribute directly from the… | |
| Aplazada | Alta (8.5) | 0.40% | — | LogtoAISamlifyAI | 10/7/2026 | 13/7/2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by string-substituting user-controlled profile attributes such as name, email, and custom attribute-mapping values into element-text… | |
| Aplazada | Alta (8.6) | 0.62% | — | Simplesamlphp-module-casserverAI | 10/6/2026 | 23/7/2026 | SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file paths for the file-based CAS ticket store by directly concatenating the configured ticket directory with an attacker-controlled ticket identifier.… | |
| Analizada | Alta (8.7) | 0.56% | — | Samlify Project Samlify | 8/6/2026 | 23/7/2026 | samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., <saml:AttributeValue>) are not escaped. A normal user can inject XML markup into an attribute value (e.g., email, name) and add new… | |
| Analizada | Alta (7.4) | 0.34% | — | Miniorange Saml SSO - Service Provider | 28/5/2026 | 21/7/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation. This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4. |