Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.24% | — | Wso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM | 23/9/2025 | 17/6/2026 | A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A single cryptographic key is used across all tenants to sign authentication cookies, allowing a privileged user in one tenant to forge authentication cookies for users in other… | |
| Analizada | Media (4.3) | 0.21% | — | Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY Manager+2 | 23/6/2025 | 17/6/2026 | An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a specific bypass method to retrieve versioned files without proper… | |
| Analizada | Media (5.2) | 0.53% | — | Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY Manager+2 | 2/6/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. A malicious actor can inject a specially crafted payload into the request, causing the browser to execute arbitrary… | |
| Analizada | Media (6.5) | 0.22% | — | Wso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAMWso2 Open Banking KM | 2/6/2025 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and external resources available through the network or filesystem.… | |
| Analizada | Media (4.3) | 0.66% | 💥 Exploit | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+2 | 30/5/2025 | 17/6/2026 | An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper authorization.… | |
| Modificada | Media (5.4) | 0.71% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+2 | 30/5/2025 | 17/6/2026 | Exploiting this vulnerability allows malicious actors to assign higher privileges to self-registered users, bypassing intended access control mechanisms. | |
| Analizada | Crítica (9.8) | 0.72% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+2 | 22/5/2025 | 17/6/2026 | An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exploit this vulnerability to reset the password of any user account, leading to a complete account takeover, including accounts with elevated… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server Analytics+4 | 18/4/2022 | 17/6/2026 | Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects… |