Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
945 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.30% | — | Cisco Identity Services Engine | 3/4/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the… | |
| Analizada | Media (5.5) | 0.37% | — | Cisco Identity Services Engine | 3/4/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker… | |
| Analizada | Alta (8.8) | 0.39% | — | Sailpoint Identityiq | 22/3/2024 | 17/6/2026 | This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population. | |
| Analizada | Alta (7.5) | 0.78% | — | Sailpoint Identityiq | 22/3/2024 | 17/6/2026 | This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional changes to the remediation announced in… | |
| Analizada | Alta (7.3) | 0.31% | — | Tenable Identity Exposure | 23/2/2024 | 17/6/2026 | A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services. | |
| Analizada | Alta (7.1) | 0.34% | — | Sailpoint Identityiq | 21/2/2024 | 17/6/2026 | An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user in an access request. | |
| Aplazada | Crítica (9.6) | 0.73% | — | German National Identity Card Online Ausweis Funktion EIDAI | 15/2/2024 | 17/6/2026 | The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify for access to government, medical, and financial resources, and can also extract personal data from the card, aka the… | |
| Modificada | Crítica (9.8) | 0.93% | — | Pingidentity Pingfederate | 6/2/2024 | 17/6/2026 | Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests. | |
| Modificada | Alta (8.8) | 0.52% | — | Pingidentity Pingdirectory | 1/2/2024 | 17/6/2026 | Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server. | |
| Modificada | Media (5.4) | 0.36% | — | Cisco Identity Services Engine | 17/1/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability exists because the web-based management interface… | |
| Modificada | Alta (8.8) | 2.2% | — | Microsoft Identitymodel Extensions | 10/1/2024 | 17/6/2026 | IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable. Microsoft.IdentityModel trusts the `jku`claim by default for… | |
| Modificada | Media (6.8) | 2.9% | — | Microsoft .netMicrosoft Identity ModelMicrosoft Visual Studio 2022 | 9/1/2024 | 17/6/2026 | Microsoft Identity Denial of service vulnerability | |
| Modificada | Alta (8.8) | 0.52% | — | Oneidentity Password Manager | 25/12/2023 | 17/6/2026 | One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: wait for a session timeout, click… | |
| Modificada | Crítica (9.8) | 1.0% | — | Oneidentity Password Manager | 25/12/2023 | 17/6/2026 | One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA… | |
| Modificada | Media (4.8) | 0.41% | — | Wso2 API ManagerWso2 API Manager AnalyticsWso2 API MicrogatewayWso2 Data Analytics Server+5 | 18/12/2023 | 17/6/2026 | Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console. | |
| Modificada | Media (6.1) | 0.43% | — | Wso2 API ManagerWso2 Identity Server AS KEY ManagerWso2 Identity Server | 15/12/2023 | 17/6/2026 | Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests. | |
| Modificada | Alta (8.2) | 0.46% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Carbon Identity Application Authentication Endpoint+1 | 15/12/2023 | 17/6/2026 | Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: Attacker should have: When all preconditions are met, a malicious actor could use JIT provisioning… | |
| Modificada | Alta (7.5) | 0.48% | — | Wso2 API ManagerWso2 API Manager AnalyticsWso2 API MicrogatewayWso2 Enterprise Integrator+3 | 15/12/2023 | 17/6/2026 | Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information. | |
| Modificada | Alta (8.8) | 0.89% | — | Cisco Identity Services Engine | 21/11/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of the application. This vulnerability is due to insufficient file input validation. An attacker could exploit this vulnerability by uploading… | |
| Modificada | Media (4.8) | 0.46% | — | Cisco Identity Services Engine | 21/11/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the web-based management interface of an affected device. | |
| Modificada | Alta (7.2) | 0.57% | — | Cisco Identity Services Engine | 1/11/2023 | 17/6/2026 | Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilities are due to improper validation of files that are uploaded… | |
| Modificada | Alta (8.8) | 0.50% | — | Cisco Identity Services Engine | 1/11/2023 | 17/6/2026 | A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Read-only-level privileges or higher on the affected… | |
| Modificada | Media (6.7) | 0.46% | — | Cisco Identity Services Engine | 1/11/2023 | 17/6/2026 | A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This… | |
| Modificada | Media (4.3) | 0.30% | — | Cisco Identity Services Engine | 1/11/2023 | 17/6/2026 | A vulnerability in the CDP processing feature of Cisco ISE could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of the CDP process on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes CDP traffic. An attacker could… | |
| Modificada | Alta (7.2) | 0.57% | — | Cisco Identity Services Engine | 1/11/2023 | 17/6/2026 | Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilities are due to improper validation of files that are uploaded… |