Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | — | EMC RSA Authentication Manager | 31/10/2017 | 17/6/2026 | EMC RSA Authentication Manager 8.2 SP1 P4 and earlier contains a reflected cross-site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Alta (8.8) | 1.2% | — | Cloudfoundry Cf-releaseCloudfoundry User Account AND AuthenticationCloudfoundry Uaa-releasePivotal Elastic Runtime | 7/9/2017 | 17/6/2026 | The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations… | |
| Modificada | Alta (7.8) | 1.5% | — | Moj.go Commercial Registration Electronic Authentication Software | 29/8/2017 | 17/6/2026 | Untrusted search path vulnerability in The electronic authentication system based on the commercial registration system "The CRCA user's Software" Ver1.8 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Crítica (9.8) | 2.9% | — | Ldap / SSO Authentication Project Ldap / SSO Authentication | 28/8/2017 | 17/6/2026 | Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3. | |
| Modificada | Media (5.9) | 2.1% | — | EMC RSA Authentication Manager | 17/7/2017 | 17/6/2026 | In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute force attack to attempt to identify that user's PIN. The malicious user could potentially reset the compromised PIN to affect victim's… | |
| Modificada | Media (4.8) | 0.90% | — | EMC RSA Authentication Manager | 17/7/2017 | 17/6/2026 | In EMC RSA Authentication Manager 8.2 SP1 and earlier, a malicious RSA Security Console Administrator could craft a token profile and store the profile name in the RSA Authentication Manager database. The profile name could include a crafted script (with an XSS payload) that could be executed when viewing or editing… | |
| Modificada | Media (5.4) | 0.83% | — | RSA Adaptive Authentication (ON Premise) | 19/5/2017 | 17/6/2026 | EMC RSA Adaptive Authentication (On-Premise) versions prior to 7.3 P2 (exclusive) contains a fix for a cross-site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Alta (7.5) | 36% | — | SAP SSO Authentication Library | 14/4/2017 | 17/6/2026 | SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in the width and height parameters to otp_logon_ui_resources/qr, aka SAP Security Note 2389042. | |
| Modificada | Media (5.4) | 1.1% | — | EMC RSA Adaptive Authentication On-premise | 21/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Case Management application in EMC RSA Adaptive Authentication (On-Premise) before 6.0.2.1.SP3.P4 HF210, 7.0.x and 7.1.x before 7.1.0.0.SP0.P6 HF50, and 7.2.x before 7.2.0.0.SP0.P0 HF20 allows remote authenticated users to inject arbitrary web script or HTML via… | |
| Modificada | Alta (8.1) | 2.2% | — | EMC Authentication Manager Prime | 22/8/2016 | 17/6/2026 | The Self-Service Portal in EMC RSA Authentication Manager (AM) Prime Self-Service 3.0 and 3.1 before 3.1 1915.42871 allows remote authenticated users to cause a denial of service (PIN change for an arbitrary user) via a modified token serial number within a PIN change request, related to a "direct object reference… | |
| Modificada | Media (5.3) | 2.1% | — | EMC RSA Authentication Manager | 7/5/2016 | 17/6/2026 | CRLF injection vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | |
| Modificada | Media (6.1) | 1.6% | — | EMC RSA Authentication Manager | 7/5/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0900. | |
| Modificada | Media (6.1) | 1.6% | — | EMC RSA Authentication Manager | 7/5/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0901. | |
| Modificada | Alta (7.8) | 0.52% | — | Dell Pre-boot Authentication Driver | 8/1/2016 | 17/6/2026 | Dell Pre-Boot Authentication Driver (PBADRV.sys) 1.0.1.5 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x0022201c IOCTL call. | |
| Modificada | Baja (2.1) | 1.5% | — | Niif Shibboleth Authentication | 18/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Shibboleth authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x before 7.x-4.2 for Drupal allows remote authenticated users with the "Administer blocks" permission to inject arbitrary web script or HTML via unspecified vectors related to a login link. | |
| Modificada | Media (5) | 1.4% | — | Services Basic Authentication Project Services Basic Authentication | 15/6/2015 | 17/6/2026 | The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vectors related to page caching. | |
| Modificada | Media (5.8) | 0.64% | — | Niif Shibboleth Authentication | 21/4/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Shibboleth Authentication module before 6.x-4.1 and 7.x-4.x before 7.x-4.1 for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete user role matching rules via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.8% | — | Apereo Central Authentication Service | 10/2/2015 | 17/6/2026 | Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication. | |
| Modificada | Alta (7.8) | 3.8% | — | Safenet-inc Safenet Authentication Service Outlook WEB Access Agent | 16/12/2014 | 17/6/2026 | Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard) before 1.03.30109 allows remote attackers to read arbitrary files via a .. (dot dot) in the GetFile parameter to owa/owa. | |
| Modificada | Media (5.8) | 1.6% | — | EMC RSA Authentication Manager | 12/12/2014 | 17/6/2026 | Open redirect vulnerability in EMC RSA Authentication Manager 8.x before 8.1 Patch 6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (5) | 1.7% | — | EMC RSA Adaptive Authentication On-premise | 8/12/2014 | 17/6/2026 | RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters with Out-of-Band Phone (Authentify) functionality, conducts permanent device binding even when authentication fails, which allows remote… | |
| Modificada | Media (4.3) | 2.0% | — | EMC RSA Adaptive Authentication Hosted | 4/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in rsa_fso.swf in EMC RSA Adaptive Authentication (Hosted) 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 0.98% | — | EMC RSA Adaptive Authentication On-premise | 4/4/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in RSA Adaptive Authentication (On-Premise) 6.x and 7.x before 7.1 SP0 P2 allows remote attackers to inject arbitrary web script or HTML via vectors involving FRAME elements, related to a "cross-frame scripting" issue. | |
| Modificada | Media (4.3) | 0.98% | — | EMC RSA Adaptive Authentication On-premise | 4/4/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the back-office case-management application in RSA Adaptive Authentication (On-Premise) 6.x and 7.x before 7.1 SP0 P2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 0.98% | — | EMC RSA Authentication Manager | 27/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Self-Service Console in EMC RSA Authentication Manager 7.1 before SP4 P32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "cross frame scripting" issue. |