Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
945 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.45% | — | Pingidentity Pingid Integration FOR Windows Login | 4/5/2022 | 17/6/2026 | Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials. | |
| Modificada | Alta (7.7) | 0.88% | — | Pingidentity Pingone MFA Integration KIT | 2/5/2022 | 17/6/2026 | An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication flow. | |
| Modificada | Media (6.5) | 0.61% | — | Pingidentity Pingfederate | 2/5/2022 | 17/6/2026 | When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password. | |
| Modificada | Crítica (9.9) | 0.51% | — | Pingidentity Pingid Desktop | 30/4/2022 | 17/6/2026 | PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP. | |
| Modificada | Media (4.8) | 0.24% | — | Pingidentity PingidPingidentity Pingid Windows Login | 30/4/2022 | 17/6/2026 | A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login. | |
| Modificada | Media (4.8) | 0.24% | — | Pingidentity PingidPingidentity Pingid Windows Login | 30/4/2022 | 17/6/2026 | A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login. | |
| Modificada | Media (5.6) | 0.50% | — | Pingidentity Pingid Integration FOR Windows Login | 30/4/2022 | 17/6/2026 | A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass. | |
| Modificada | Media (6.1) | 41% | 💥 Exploit | Wso2 API ManagerWso2 API Manager AnalyticsWso2 API MicrogatewayWso2 Data Analytics Server+5 | 21/4/2022 | 17/6/2026 | A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0;… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server Analytics+4 | 18/4/2022 | 17/6/2026 | Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects… | |
| Modificada | Alta (7.8) | 0.29% | — | Juniper Identity Management Service | 14/4/2022 | 17/6/2026 | An Improper Privilege Management vulnerability in the Windows Installer framework used in the Juniper Networks Juniper Identity Management Service (JIMS) allows an unprivileged user to trigger a repair operation. Running a repair operation, in turn, will trigger a number of file operations in the %TEMP% folder of the… | |
| Modificada | Media (5.3) | 0.85% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims. | |
| Analizada | Alta (7.8) | 36% | ⚠ Explotación activa💥 Exploit | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'. | |
| Modificada | Media (4.3) | 0.51% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI. | |
| Modificada | Alta (7.2) | 3.1% | — | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution. | |
| Modificada | Alta (7.2) | 24% | 💥 Exploit | Vmware Cloud FoundationVmware Identity ManagerVmware Vrealize AutomationVmware Vrealize Suite Lifecycle Manager+1 | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution. | |
| Modificada | Crítica (9.8) | 50% | 💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework. | |
| Modificada | Crítica (9.8) | 7.8% | — | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access | 13/4/2022 | 17/6/2026 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE AccessVmware Cloud Foundation+1 | 11/4/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. | |
| Modificada | Media (6.5) | 1.0% | — | Cisco Identity Services Engine | 6/4/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to improper enforcement of administrative privilege levels for high-value sensitive data. An… | |
| Modificada | Alta (7.5) | 1.5% | — | Cisco Identity Services Engine | 6/4/2022 | 17/6/2026 | A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Modificada | Media (5.3) | 1.1% | — | Cyberark Identity | 3/3/2022 | 17/6/2026 | CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value ranges which can be used to determine whether a user exists in the tenant. | |
| Modificada | Media (6.5) | 0.53% | — | Pingidentity Pingfederate | 10/2/2022 | 17/6/2026 | When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password. | |
| Modificada | Media (5.3) | 0.95% | — | Saviynt Enterprise Identity Cloud | 24/1/2022 | 17/6/2026 | An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changing the id parameter, such as for the ECM/maintenance/forgotpasswordstep1 URI. | |
| Modificada | Crítica (9.8) | 1.7% | — | Saviynt Enterprise Identity Cloud | 24/1/2022 | 17/6/2026 | An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to reset passwords and login as any local account. |