Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

290 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.6%—Checkpoint Session Authentication Agent26/1/201417/6/2026
Check Point Session Authentication Agent allows remote attackers to obtain sensitive information (user credentials) via unspecified vectors.
ModificadaBaja (3.5)1.2%—Vasco Identikey Authentication Server13/1/201417/6/2026
VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by entering only a DIGIPASS one-time password, instead of the intended combination of this one-time password and a multiple-time AD password.
ModificadaAlta (7.5)2.3%—EMC RSA Authentication Agent25/10/201316/6/2026
EMC RSA Authentication Agent 7.1.x before 7.1.2 for Web for Internet Information Services has a fail-open design, which allows remote attackers to bypass intended access restrictions via vectors that trigger an agent crash.
ModificadaMedia (5)1.3%—EMC RSA Authentication Agent28/8/201316/6/2026
EMC RSA Authentication Agent for PAM 7.0 before 7.0.2.1 enforces the maximum number of login attempts within the PAM-enabled application codebase, instead of within the Agent codebase, which makes it easier for remote attackers to discover correct login credentials via a brute-force attack.
ModificadaBaja (2.1)0.34%—EMC RSA Authentication ManagerRSA Authentication Manager8/7/201316/6/2026
EMC RSA Authentication Manager 8.0 before P2 and 7.1 before SP4 P26, as used in Appliance 3.0, does not omit the cleartext administrative password from trace logging in custom SDK applications, which allows local users to obtain sensitive information by reading the trace log file.
ModificadaMedia (5)4.4%💥 ExploitDS3 Authentication Server28/6/201316/6/2026
ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter.
ModificadaMedia (5)7.3%💥 ExploitDS3 Authentication Server28/6/201316/6/2026
ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in a -REG-E-OPEN error message.
ModificadaAlta (9)9.1%💥 ExploitDS3 Authentication Server28/6/201316/6/2026
ServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary commands via shell metacharacters in the HOST_NAME field.
ModificadaBaja (2.1)0.34%—RSA Authentication Manager7/6/201316/6/2026
EMC RSA Authentication Manager 8.0 before P1 allows local users to discover cleartext operating-system passwords, HTTP plug-in proxy passwords, and SNMP communities by reading a (1) log file or (2) configuration file.
ModificadaMedia (4.3)2.4%—EMC RSA Authentication Agent22/5/201316/6/2026
Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Agent 7.1 before 7.1.1 for Web for Internet Information Services, and 7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (2.1)1.3%—RSA Authentication APIRSA Securid WEB AgentRSA Pluggable Authentication Module AgentRSA Authentication Agent22/5/201316/6/2026
EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the…
ModificadaAlta (7.5)2.6%—HP Tacacs+ Authentication Manager9/3/201316/6/2026
Unspecified vulnerability in HP Intelligent Management Center (iMC) TACACS+ Authentication Manager (TAM) before 5.2 E0401 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1646.
ModificadaMedia (5.4)0.55%—RSA Authentication Agent FOR Windows5/3/201316/6/2026
EMC RSA Authentication Agent 7.1.x before 7.1.2 on Windows does not enforce the Quick PIN Unlock timeout feature, which allows physically proximate attackers to bypass the passcode requirement for a screensaved session by entering a PIN after timeout expiration.
ModificadaMedia (4.3)1.4%—EMC RSA Adaptive Authentication On-premise27/11/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Adaptive Authentication On-Premise (AAOP) before 7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (2.9)0.55%—EMC RSA Adaptive Authentication On-premise10/10/201216/6/2026
Unspecified vulnerability in EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 before SP3 P3 allows remote attackers to obtain sensitive information via unknown vectors.
ModificadaAlta (8.5)2.7%—EMC RSA Authentication AgentEMC RSA Authentication Client25/9/201216/6/2026
The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to bypass an intended token-authentication step, and establish a login session to a remote host, by…
ModificadaMedia (5)1.1%—EMC RSA Authentication ManagerRSA Authentication ManagerRSA Securid Appliance13/7/201216/6/2026
EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 do not properly use frames, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "Cross frame scripting vulnerability."
ModificadaMedia (6.4)1.3%—EMC RSA Authentication ManagerRSA Authentication ManagerRSA Securid Appliance13/7/201216/6/2026
Open redirect vulnerability in the Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (4.3)0.98%—EMC RSA Authentication ManagerRSA Authentication ManagerRSA Securid Appliance13/7/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Self-Service Console and (2) Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)1.2%—EMC RSA Adaptive Authentication On-premise14/12/201116/6/2026
EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly perform forensic evaluation upon receipt of device tokens from mobile apps, which might allow remote attackers to bypass intended application restrictions via a mobile device.
ModificadaMedia (6.8)1.2%—EMC RSA Adaptive Authentication On-premise14/12/201116/6/2026
EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly implement Device Recovery and Device Identification, which might allow remote attackers to bypass intended security restrictions on a (1) previously non-registered device or (2) registered…
ModificadaAlta (7.5)1.1%💥 ExploitAuthenex Strong Authentication System Server14/12/201116/6/2026
SQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authentication System (ASAS) Server 3.1.0.2 and 3.1.0.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaAlta (7.5)1.3%—EMC RSA Adaptive Authentication On-premise18/8/201116/6/2026
EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not prevent reuse of authentication information during a session, which allows remote authenticated users to bypass intended access restrictions via vectors related to knowledge of the originally used…
ModificadaMedia (5.8)1.4%—Arcot Webfort Versatile Authentication Server5/5/201116/6/2026
Open redirect vulnerability in the Administrative Console in CA Arcot WebFort Versatile Authentication Server (VAS) before 6.2.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (4.3)1.3%—Arcot Webfort Versatile Authentication Server5/5/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Administrative Console in CA Arcot WebFort Versatile Authentication Server (VAS) before 6.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.