Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
945 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.69% | — | Pingidentity Pingid Radius PCV | 25/10/2023 | 17/6/2026 | A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request. | |
| Modificada | Media (6.5) | 0.53% | — | Pingidentity Pingone MFA Integration KIT | 25/10/2023 | 17/6/2026 | PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials. | |
| Modificada | Alta (7.5) | 0.59% | — | Pingidentity Pingfederate | 25/10/2023 | 17/6/2026 | PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests | |
| Modificada | Crítica (9.8) | 0.75% | — | Pingidentity Pingfederate | 25/10/2023 | 17/6/2026 | Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter | |
| Modificada | Media (4.3) | 0.47% | — | Pingidentity Pingfederate | 25/10/2023 | 17/6/2026 | When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request | |
| Modificada | Crítica (9.6) | 1.1% | — | Xwiki Oauth Identity | 16/10/2023 | 17/6/2026 | com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and XWiki syntax injection. This allows… | |
| Modificada | Alta (8.8) | 1.6% | — | Microsoft Azure Identity SDK | 10/10/2023 | 17/6/2026 | Azure Identity SDK Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 2.2% | — | Microsoft Azure Identity SDK | 10/10/2023 | 17/6/2026 | Azure Identity SDK Remote Code Execution Vulnerability | |
| Modificada | Media (6.8) | 0.54% | — | Oneidentity Password Manager | 27/9/2023 | 17/6/2026 | One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges. | |
| Modificada | Media (5.4) | 0.32% | — | Symantec Identity Portal | 19/9/2023 | 17/6/2026 | An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4 | |
| Modificada | Media (4.4) | 1.4% | — | Microsoft Identity Linux Broker | 12/9/2023 | 17/6/2026 | Microsoft Identity Linux Broker Remote Code Execution Vulnerability | |
| Modificada | Media (4.9) | 0.72% | — | Cisco Identity Services Engine | 7/9/2023 | 17/6/2026 | A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to… | |
| Analizada | Media (6.7) | 0.20% | — | Cisco Identity Services Engine | 7/9/2023 | 21/9/2026 | A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on… | |
| Modificada | Alta (8.6) | 0.92% | — | Cisco Identity Services Engine | 6/9/2023 | 17/6/2026 | A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS accounting requests. An attacker could… | |
| Modificada | Media (6.5) | 0.74% | — | Cisco Identity Services Engine | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within the web-based management interface. An attacker could exploit… | |
| Modificada | Media (5.3) | 0.51% | — | Jenkins Chef Identity | 26/7/2023 | 17/6/2026 | Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it. | |
| Modificada | Crítica (9.8) | 1.3% | — | Openidentityplatform Openam | 20/7/2023 | 17/6/2026 | Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of SAML responses received as part of the SAMLv1.x Single Sign-On process.… | |
| Modificada | Media (5.3) | 0.63% | — | Umbraco Identity Extensibility | 9/6/2023 | 17/6/2026 | UmbracoIdentityExtensions is an Umbraco add-on package that enables easy extensibility points for ASP.Net Identity integration. In affected versions client secrets are not required which may expose some endpoints to untrusted actors. Since Umbraco is not a single-page application, the implicit flow is not safe. For… | |
| Modificada | Alta (8.8) | 0.63% | — | Sailpoint Identityiq | 5/6/2023 | 17/6/2026 | IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor… | |
| Modificada | Media (6.1) | 0.35% | — | Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Identity Manager Connector | 30/5/2023 | 17/6/2026 | VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure. | |
| Modificada | Media (6.1) | 3.3% | 💥 Exploit | Ellucian Ethos Identity | 20/5/2023 | 17/6/2026 | A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Media (4.9) | 0.72% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid… | |
| Modificada | Media (4.9) | 0.77% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid… | |
| Modificada | Media (4.9) | 0.40% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,… | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,… |