Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

945 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.69%—Pingidentity Pingid Radius PCV25/10/202317/6/2026
A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request.
ModificadaMedia (6.5)0.53%—Pingidentity Pingone MFA Integration KIT25/10/202317/6/2026
PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.
ModificadaAlta (7.5)0.59%—Pingidentity Pingfederate25/10/202317/6/2026
PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests
ModificadaCrítica (9.8)0.75%—Pingidentity Pingfederate25/10/202317/6/2026
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
ModificadaMedia (4.3)0.47%—Pingidentity Pingfederate25/10/202317/6/2026
When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request
ModificadaCrítica (9.6)1.1%—Xwiki Oauth Identity16/10/202317/6/2026
com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and XWiki syntax injection. This allows…
ModificadaAlta (8.8)1.6%—Microsoft Azure Identity SDK10/10/202317/6/2026
Azure Identity SDK Remote Code Execution Vulnerability
ModificadaAlta (8.8)2.2%—Microsoft Azure Identity SDK10/10/202317/6/2026
Azure Identity SDK Remote Code Execution Vulnerability
ModificadaMedia (6.8)0.54%—Oneidentity Password Manager27/9/202317/6/2026
One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges.
ModificadaMedia (5.4)0.32%—Symantec Identity Portal19/9/202317/6/2026
An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4
ModificadaMedia (4.4)1.4%—Microsoft Identity Linux Broker12/9/202317/6/2026
Microsoft Identity Linux Broker Remote Code Execution Vulnerability
ModificadaMedia (4.9)0.72%—Cisco Identity Services Engine7/9/202317/6/2026
A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to…
AnalizadaMedia (6.7)0.20%—Cisco Identity Services Engine7/9/202321/9/2026
A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on…
ModificadaAlta (8.6)0.92%—Cisco Identity Services Engine6/9/202317/6/2026
A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS accounting requests. An attacker could…
ModificadaMedia (6.5)0.74%—Cisco Identity Services Engine16/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within the web-based management interface. An attacker could exploit…
ModificadaMedia (5.3)0.51%—Jenkins Chef Identity26/7/202317/6/2026
Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.
ModificadaCrítica (9.8)1.3%—Openidentityplatform Openam20/7/202317/6/2026
Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of SAML responses received as part of the SAMLv1.x Single Sign-On process.…
ModificadaMedia (5.3)0.63%—Umbraco Identity Extensibility9/6/202317/6/2026
UmbracoIdentityExtensions is an Umbraco add-on package that enables easy extensibility points for ASP.Net Identity integration. In affected versions client secrets are not required which may expose some endpoints to untrusted actors. Since Umbraco is not a single-page application, the implicit flow is not safe. For…
ModificadaAlta (8.8)0.63%—Sailpoint Identityiq5/6/202317/6/2026
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor…
ModificadaMedia (6.1)0.35%—Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Identity Manager Connector30/5/202317/6/2026
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
ModificadaMedia (6.1)3.3%💥 ExploitEllucian Ethos Identity20/5/202317/6/2026
A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the…
ModificadaMedia (4.9)0.72%—Cisco Identity Services Engine18/5/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid…
ModificadaMedia (4.9)0.77%—Cisco Identity Services Engine18/5/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid…
ModificadaMedia (4.9)0.40%—Cisco Identity Services Engine18/5/202317/6/2026
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,…
ModificadaMedia (6.5)0.38%—Cisco Identity Services Engine18/5/202317/6/2026
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,…