Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
945 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.51% | — | Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager | 26/1/2023 | 17/6/2026 | User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses. | |
| Modificada | Media (5.4) | 0.56% | — | Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager | 26/1/2023 | 17/6/2026 | An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser. | |
| Modificada | Media (5.3) | 0.46% | — | Netiq Identity Manager | 26/1/2023 | 17/6/2026 | File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versions prior to 4.8.5 on ALL. | |
| Modificada | Alta (7.5) | 2.4% | 💥 PoC | Oneidentity Syslog-ngOneidentity Syslog-ng Store BOX | 23/1/2023 | 17/6/2026 | An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected. | |
| Modificada | Media (5.4) | 0.54% | — | Cisco Identity Services Engine | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an… | |
| Modificada | Media (5.4) | 28% | — | Cisco Identity Services Engine | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an… | |
| Modificada | Media (5.4) | 0.61% | — | Cisco Identity Services Engine | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerability is due to improper access control on a feature within the web-based management interface of the… | |
| Modificada | Alta (8.8) | 31% | — | Cisco Identity Services Engine | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user input within requests as part of the web-based management… | |
| Modificada | Media (5.3) | 0.74% | — | Microsoft Azure AD POD Identity | 21/12/2022 | 17/6/2026 | aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request made with backslash in the request (example:… | |
| Modificada | Alta (8.8) | 0.91% | — | Broadcom Symantec Identity Governance AND Administration | 16/12/2022 | 17/6/2026 | An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4 | |
| Modificada | Media (6.7) | 0.94% | — | Broadcom Symantec Identity Governance AND Administration | 16/12/2022 | 17/6/2026 | An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4 | |
| Modificada | Media (5.3) | 0.71% | — | Broadcom Symantec Identity Governance AND Administration | 16/12/2022 | 17/6/2026 | An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session. | |
| Modificada | Media (5.3) | 0.52% | — | Vmware AccessVmware Cloud FoundationVmware Identity Manager Connector | 14/12/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3. | |
| Modificada | Alta (7.2) | 1.1% | — | Vmware AccessVmware Cloud FoundationVmware Identity Manager | 14/12/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2. | |
| Modificada | Media (5.4) | 0.46% | — | Cisco Identity Services Engine | 4/11/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Modificada | Alta (8.8) | 1.0% | — | Cisco Identity Services Engine | 4/11/2022 | 17/6/2026 | A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (8.8) | 0.43% | — | Cisco Identity Services Engine | 4/11/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the… | |
| Modificada | Alta (8.8) | 1.4% | — | Cisco Identity Services Engine | 4/11/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker… | |
| Modificada | Media (5.3) | 0.88% | — | Cisco Identity Services Engine | 4/11/2022 | 17/6/2026 | A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device. This vulnerability is due to insufficient management of system resources. An attacker could exploit… | |
| Modificada | Media (5.4) | 0.84% | — | Cisco Identity Services Engine | 26/10/2022 | 17/6/2026 | A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient input validation. An… | |
| Modificada | Alta (8.1) | 1.3% | — | Cisco Identity Services Engine | 26/10/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by… | |
| Modificada | Media (4.9) | 0.69% | — | Pingidentity Pingcentral | 30/9/2022 | 17/6/2026 | PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information. | |
| Modificada | Alta (7.5) | 0.85% | — | Identity AND Directory Management System Project Identity AND Directory Management System | 21/9/2022 | 17/6/2026 | The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vulnerability. This has been fixed in the version 2.1.25 | |
| Modificada | Media (6.1) | 0.48% | — | IBM Security Identity Manager | 30/8/2022 | 17/6/2026 | IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site… | |
| Modificada | Media (4.9) | 0.95% | — | Cisco Identity Services Engine | 10/8/2022 | 17/6/2026 | A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API output. An attacker could exploit this vulnerability by… |