Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
945 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.47% | — | Cisco Identity Services Engine | 4/9/2024 | 17/6/2026 | A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid Administrator privileges on… | |
| Aplazada | Crítica (9.8) | 51% | 💥 Exploit | Oneidentity Safeguard FOR Privileged PasswordsAI | 30/8/2024 | 17/6/2026 | One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2. | |
| Analizada | Media (4.3) | 0.32% | — | Cyberark Identity | 25/8/2024 | 17/6/2026 | CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security | |
| Analizada | Media (4.3) | 0.29% | — | Cyberark Identity | 25/8/2024 | 17/6/2026 | CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |
| Analizada | Media (4.3) | 0.29% | — | Cyberark Identity | 25/8/2024 | 17/6/2026 | CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |
| Analizada | Media (6.5) | 0.31% | — | Cyberark Identity | 25/8/2024 | 17/6/2026 | CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |
| Analizada | Alta (8.8) | 0.28% | — | Cisco Identity Services Engine | 21/8/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the… | |
| Analizada | Media (4.9) | 0.48% | — | Cisco Identity Services Engine | 21/8/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to improper enforcement of administrative privilege levels for high-value sensitive data. An… | |
| Analizada | Alta (8.1) | 0.50% | — | Cisco Identity Services Engine | 21/8/2024 | 17/6/2026 | Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks. These vulnerabilities are due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit these vulnerabilities by… | |
| Analizada | Media (5.4) | 0.29% | — | Cisco Identity Services Engine | 7/8/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker… | |
| Analizada | Media (4.8) | 0.29% | — | Cisco Identity Services Engine | 7/8/2024 | 21/9/2026 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker… | |
| Aplazada | Media (4.7) | 0.53% | — | Duende IdentityserverAIMicrosoft Asp.net CoreAI | 31/7/2024 | 17/6/2026 | Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url is returned as a redirect, some browsers will follow it to a third-party,… | |
| Analizada | Alta (7.2) | 0.47% | — | Cisco Identity Services Engine | 17/7/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit this vulnerability, an attacker would need at least valid Policy Admin credentials on the affected device. This… | |
| Analizada | Media (6.8) | 0.47% | — | Tenable Identity Exposure | 16/7/2024 | 17/6/2026 | A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232 | |
| Modificada | Media (4.3) | 0.17% | — | Pingidentity Pingfederate | 9/7/2024 | 17/6/2026 | A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only. | |
| Modificada | Media (5.3) | 0.44% | — | Pingidentity Pingfederate | 9/7/2024 | 17/6/2026 | The deploy directory in PingFederate runtime nodes is reachable to unauthorized users. | |
| Aplazada | Baja (3.5) | 0.24% | — | Pingidentity PingfederateAI | 9/7/2024 | 17/6/2026 | A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body. | |
| Aplazada | Alta (8.7) | 0.40% | — | Pingidentity Pingone MFA Integration KITAI | 9/7/2024 | 17/6/2026 | PingOne MFA Integration Kit contains a vulnerability related to the Prompt Users to Set Up MFA configuration. Under certain conditions, this configuration could allow for a new MFA device to be paired with a target user account without requiring second-factor authentication from the target’s existing registered… | |
| Modificada | Media (5.5) | 0.83% | — | Microsoft Authentication LibraryMicrosoft Azure Identity SDK | 11/6/2024 | 20/7/2026 | Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | |
| Aplazada | Alta (8.8) | 0.55% | — | Pingidentity PingaccessAI | 31/5/2024 | 17/6/2026 | HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a request smuggling condition for proxied requests. | |
| Aplazada | Crítica (9.1) | 0.80% | — | Sailpoint Identity Security CloudAI | 15/5/2024 | 17/6/2026 | An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host. | |
| Aplazada | Media (6.5) | 0.44% | — | Sailpoint Identity Security CloudAI | 15/5/2024 | 17/6/2026 | An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants. | |
| Analizada | Alta (7.3) | 0.15% | — | Checkpoint Identity AgentCheckpoint Zonealarm Extreme Security Nextgen | 18/4/2024 | 17/6/2026 | A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system. | |
| Aplazada | Media (6.5) | 0.46% | — | Pingidentity PingfederateAI | 10/4/2024 | 17/6/2026 | Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and consume server-side resources via forged HTTP POST requests. | |
| Analizada | Media (5.5) | 0.72% | — | Microsoft Azure Identity | 9/4/2024 | 24/9/2026 | Azure Identity Library for .NET Information Disclosure Vulnerability |