Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

945 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)2.4%—Vmware Identity ManagerVmware ONE AccessVmware Identity Manager Connector5/8/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.
ModificadaAlta (7.8)0.33%—Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector5/8/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
ModificadaMedia (6.1)0.67%—Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector5/8/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
ModificadaAlta (7.5)1.2%—Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector5/8/202217/6/2026
VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files.
ModificadaAlta (7.8)0.33%—Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector5/8/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'.
ModificadaAlta (7.8)1.1%💥 ExploitVmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector5/8/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
ModificadaAlta (7.2)2.9%—Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector5/8/202217/6/2026
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.
ModificadaAlta (7.2)2.2%—Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector5/8/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.
ModificadaCrítica (9.8)1.4%—Vmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector5/8/202217/6/2026
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.
ModificadaCrítica (9.8)24%💥 ExploitVmware Identity ManagerVmware ONE AccessVmware Access ConnectorVmware Identity Manager Connector5/8/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
ModificadaMedia (5.5)0.21%—Pingidentity Pingid Integration FOR Windows Login30/6/202217/6/2026
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
ModificadaAlta (8.2)0.24%—Pingidentity Pingid Integration FOR Windows Login30/6/202217/6/2026
PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT administrator could mistakenly deploy administrator privileged PingID API credentials, such as those typically used by PingFederate, into PingID Windows Login user…
ModificadaMedia (6.4)0.29%—Pingidentity Pingid Integration FOR Windows Login30/6/202217/6/2026
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the local Java service using multiple attack vectors. A successful attack can lead to…
ModificadaAlta (8.1)2.1%—Pingidentity Pingid Integration FOR Windows Login30/6/202217/6/2026
PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login…
ModificadaMedia (5.5)0.23%—Pingidentity Pingid Integration FOR Windows Login30/6/202217/6/2026
PingID Windows Login prior to 2.8 is vulnerable to a denial of service condition on local machines when combined with using offline security keys as part of authentication.
ModificadaAlta (7.5)0.78%—Pingidentity Pingid Integration FOR MAC Login30/6/202217/6/2026
A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
ModificadaMedia (5.3)3.2%💥 PoCOpenidentityplatform Openam23/6/202217/6/2026
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
ModificadaMedia (6.5)0.97%—Cisco Identity Services Engine15/6/202217/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because administrative privilege levels for sensitive data are not properly enforced. An…
ModificadaCrítica (9.8)1.1%—Cisco Identity Services Engine15/6/202217/6/2026
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could…
ModificadaAlta (7.8)2.4%—Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Vrealize Suite Lifecycle Manager20/5/202217/6/2026
VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
ModificadaCrítica (9.8)56%💥 ExploitVmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+120/5/202217/6/2026
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
ModificadaMedia (5.9)0.73%—IBM Security Identity Manager19/5/202217/6/2026
IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…
ModificadaMedia (5.3)0.91%—IBM Security Identity Governance AND Intelligence17/5/202217/6/2026
IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information in URL parameters that could aid in future attacks against the system. IBM X-Force ID: 192208.
ModificadaCrítica (9.1)3.8%—Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager11/5/202217/6/2026
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to…
ModificadaMedia (6.1)0.63%—Identityserver4.admin Project Identityserver4.admin11/5/202217/6/2026
A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter.
Orbitaley — Vulnerabilidades