Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

2624 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.51%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.…
AnalizadaCrítica (9.1)0.49%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager. While…
AnalizadaCrítica (9.9)0.43%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While…
AnalizadaCrítica (9.1)0.43%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.…
AnalizadaAlta (8.6)0.41%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While…
AnalizadaCrítica (9.8)0.51%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Access Manager.…
AnalizadaAlta (8.7)0.41%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager. While…
AnalizadaCrítica (9.9)0.39%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While…
AnalizadaCrítica (10)0.51%—Oracle Access Manager15/9/202621/9/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While…
Pendiente de análisisAlta (7.5)0.39%—IBM Verify Identity AccessAI15/9/202616/9/2026
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Pendiente de análisisAlta (7.2)0.32%—IBM Verify Identity AccessAI15/9/202616/9/2026
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
Pendiente de análisisAlta (7.5)0.16%—IBM Security Verify Identity Access Reverse ProxyAI15/9/202616/9/2026
IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Pendiente de análisisCrítica (9.8)0.29%—IBM Verify Identity AccessAI15/9/202617/9/2026
IBM Verify Identity Access is vulnerable to a buffer overflow attack.
Pendiente de análisisAlta (7.5)0.31%—IBM Verify Identity AccessAI15/9/202616/9/2026
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Pendiente de análisisCrítica (9.1)0.23%—IBM Verify Identity AccessAI15/9/202617/9/2026
IBM Verify Identity Access containers may not apply management password change operations correctly.
Pendiente de análisisAlta (8.1)0.27%—IBM Verify Identity AccessAI15/9/202619/9/2026
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.
Pendiente de análisisMedia (6.5)0.17%—IBM Security Verify Identity AccessAI15/9/202619/9/2026
IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.
Pendiente de análisisMedia (6.3)0.50%—IBM I Access FamilyAI14/9/202617/9/2026
IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file.
Pendiente de análisisMedia (6.3)0.27%—IBM I Access FamilyAIIBM I Access Client SolutionsAI14/9/202617/9/2026
IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action.
Pendiente de análisisMedia (6.3)0.27%—IBM I Access FamilyAIIBM I Access Client SolutionsAI14/9/202617/9/2026
IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command.
Pendiente de análisisMedia (4.7)0.28%—IBM Verify Identity AccessAI14/9/202616/9/2026
IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear…
Pendiente de análisisMedia (6.1)0.24%—IBM Verify Identity AccessAIIBM Security Verify AccessAIIBM Verify Identity Access ContainerAIIBM Security Verify Access ContainerAI14/9/202616/9/2026
IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001.
Pendiente de análisisAlta (7.5)0.43%—IBM Verify Identity AccessAI14/9/202616/9/2026
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Pendiente de análisisMedia (5.4)0.15%—IBM Verify Identity AccessAI14/9/202619/9/2026
IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.
AplazadaAlta (7.1)0.29%—Hikvision Hikcentral Access ControlAI10/9/202610/9/2026
There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access.