Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
944 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.25% | — | Wso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM | 26/9/2025 | 17/6/2026 | A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system returns a distinct "User does not exist" error message to the login form, regardless of the validate_username setting. This behavior allows malicious actors to determine which… | |
| Analizada | Baja (3.8) | 0.21% | — | Wso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM | 23/9/2025 | 17/6/2026 | An authentication bypass vulnerability exists in multiple WSO2 products when FIDO authentication is enabled. When a user account is deleted, the system does not automatically remove associated FIDO registration data. If a new user account is later created using the same username, the system may associate the new… | |
| Analizada | Media (6.1) | 0.23% | — | Wso2 Identity Server | 23/9/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due to improper output encoding. A malicious actor can exploit this vulnerability by injecting a crafted payload that is reflected in the server response, enabling the execution of arbitrary JavaScript… | |
| Analizada | Media (6.8) | 0.24% | — | Wso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM | 23/9/2025 | 17/6/2026 | A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A single cryptographic key is used across all tenants to sign authentication cookies, allowing a privileged user in one tenant to forge authentication cookies for users in other… | |
| Analizada | Media (4.3) | 0.21% | — | Wso2 API ManagerWso2 Identity Server | 23/9/2025 | 17/6/2026 | A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain conditions, error messages are passed through URL parameters without validation, allowing malicious actors to inject arbitrary content into the UI. By exploiting this vulnerability, attackers can… | |
| Modificada | Media (4.6) | 1.4% | — | Quest ONE Identity | 3/9/2025 | 17/6/2026 | One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can bypass the OTP verification step by replaying the same response.… | |
| Analizada | Media (4.9) | 0.30% | — | Cisco Identity Services Engine | 20/8/2025 | 18/9/2026 | A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a… | |
| Aplazada | Media (4) | 0.24% | — | Oneidentity OneloginAI | 19/7/2025 | 17/6/2026 | In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header. | |
| Analizada | Crítica (10) | 68% | ⚠ Explotación activa | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation… | |
| Analizada | Media (4.1) | 0.42% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass configured IP access restrictions and log in to the device from a disallowed IP address. This vulnerability is due to improper enforcement of access controls that are configured… | |
| Analizada | Alta (7.2) | 19% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this… | |
| Analizada | Alta (7.2) | 9.9% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this… | |
| Aplazada | Alta (7.6) | 0.20% | — | Oneidentity Password ManagerAI | 14/7/2025 | 17/6/2026 | The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within the kiosk browser used to display the Password Self-Service site to end users. Specifically, the application attempts to restrict privileged… | |
| Aplazada | Media (5) | 0.16% | — | Oneidentity Onelogin Active Directory ConnectorAI | 2/7/2025 | 17/6/2026 | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812. | |
| Analizada | Crítica (10) | 39% | 💥 Exploit | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 25/6/2025 | 17/6/2026 | A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent… | |
| Analizada | Crítica (10) | 98% | ⚠ Explotación activa💥 Exploit | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 25/6/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation… | |
| Analizada | Media (6.4) | 0.36% | — | Cisco Identity Services Engine | 25/6/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. | |
| Analizada | Media (4.3) | 0.21% | — | Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY Manager+2 | 23/6/2025 | 17/6/2026 | An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a specific bypass method to retrieve versioned files without proper… | |
| Aplazada | Media (6.9) | 0.37% | — | Pingidentity PingfederateAI | 15/6/2025 | 17/6/2026 | Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing. | |
| Aplazada | Media (6.9) | 0.33% | — | Pingidentity PingfederateAIGoogle AdapterAI | 15/6/2025 | 17/6/2026 | Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal usage conditions. | |
| Aplazada | Baja (2.1) | 0.33% | — | Pingidentity PingfederateAI | 15/6/2025 | 17/6/2026 | PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization. | |
| Analizada | Media (6.5) | 0.35% | — | IBM Verify Identity Access Digital Credentials | 6/6/2025 | 17/6/2026 | IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a specially crafted POST request. | |
| Analizada | Media (5.3) | 0.32% | — | IBM Verify Identity Access Digital Credentials | 6/6/2025 | 17/6/2026 | IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Crítica (9.8) | 1.1% | — | Cisco Identity Services Engine | 4/6/2025 | 17/6/2026 | A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt… | |
| Analizada | Alta (7.2) | 0.51% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 4/6/2025 | 17/6/2026 | A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An… |