Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

945 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.30%—Cisco Identity Services Engine3/4/202417/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the…
AnalizadaMedia (5.5)0.37%—Cisco Identity Services Engine3/4/202417/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker…
AnalizadaAlta (8.8)0.39%—Sailpoint Identityiq22/3/202417/6/2026
This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.
AnalizadaAlta (7.5)0.78%—Sailpoint Identityiq22/3/202417/6/2026
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional changes to the remediation announced in…
AnalizadaAlta (7.3)0.31%—Tenable Identity Exposure23/2/202417/6/2026
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.
AnalizadaAlta (7.1)0.34%—Sailpoint Identityiq21/2/202417/6/2026
An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user in an access request.
AplazadaCrítica (9.6)0.73%—German National Identity Card Online Ausweis Funktion EIDAI15/2/202417/6/2026
The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify for access to government, medical, and financial resources, and can also extract personal data from the card, aka the…
ModificadaCrítica (9.8)0.93%—Pingidentity Pingfederate6/2/202417/6/2026
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
ModificadaAlta (8.8)0.52%—Pingidentity Pingdirectory1/2/202417/6/2026
Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.
ModificadaMedia (5.4)0.36%—Cisco Identity Services Engine17/1/202417/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability exists because the web-based management interface…
ModificadaAlta (8.8)2.2%—Microsoft Identitymodel Extensions10/1/202417/6/2026
IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable. Microsoft.IdentityModel trusts the `jku`claim by default for…
ModificadaMedia (6.8)2.9%—Microsoft .netMicrosoft Identity ModelMicrosoft Visual Studio 20229/1/202417/6/2026
Microsoft Identity Denial of service vulnerability
ModificadaAlta (8.8)0.52%—Oneidentity Password Manager25/12/202317/6/2026
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: wait for a session timeout, click…
ModificadaCrítica (9.8)1.0%—Oneidentity Password Manager25/12/202317/6/2026
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA…
ModificadaMedia (4.8)0.41%—Wso2 API ManagerWso2 API Manager AnalyticsWso2 API MicrogatewayWso2 Data Analytics Server+518/12/202317/6/2026
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.
ModificadaMedia (6.1)0.43%—Wso2 API ManagerWso2 Identity Server AS KEY ManagerWso2 Identity Server15/12/202317/6/2026
Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be performed in both authenticated and unauthenticated requests.
ModificadaAlta (8.2)0.46%—Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Carbon Identity Application Authentication Endpoint+115/12/202317/6/2026
Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: Attacker should have: When all preconditions are met, a malicious actor could use JIT provisioning…
ModificadaAlta (7.5)0.48%—Wso2 API ManagerWso2 API Manager AnalyticsWso2 API MicrogatewayWso2 Enterprise Integrator+315/12/202317/6/2026
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
ModificadaAlta (8.8)0.89%—Cisco Identity Services Engine21/11/202317/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of the application. This vulnerability is due to insufficient file input validation. An attacker could exploit this vulnerability by uploading…
ModificadaMedia (4.8)0.46%—Cisco Identity Services Engine21/11/202317/6/2026
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the web-based management interface of an affected device.
ModificadaAlta (7.2)0.57%—Cisco Identity Services Engine1/11/202317/6/2026
Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilities are due to improper validation of files that are uploaded…
ModificadaAlta (8.8)0.50%—Cisco Identity Services Engine1/11/202317/6/2026
A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Read-only-level privileges or higher on the affected…
ModificadaMedia (6.7)0.46%—Cisco Identity Services Engine1/11/202317/6/2026
A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This…
ModificadaMedia (4.3)0.30%—Cisco Identity Services Engine1/11/202317/6/2026
A vulnerability in the CDP processing feature of Cisco ISE could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of the CDP process on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes CDP traffic. An attacker could…
ModificadaAlta (7.2)0.57%—Cisco Identity Services Engine1/11/202317/6/2026
Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilities are due to improper validation of files that are uploaded…
Orbitaley — Vulnerabilidades