Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.8)0.24%—Wso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM23/9/202517/6/2026
A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A single cryptographic key is used across all tenants to sign authentication cookies, allowing a privileged user in one tenant to forge authentication cookies for users in other…
AnalizadaMedia (4.3)0.21%—Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY Manager+223/6/202517/6/2026
An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a specific bypass method to retrieve versioned files without proper…
AnalizadaMedia (5.2)0.53%—Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY Manager+22/6/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. A malicious actor can inject a specially crafted payload into the request, causing the browser to execute arbitrary…
AnalizadaMedia (6.5)0.22%—Wso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAMWso2 Open Banking KM2/6/202517/6/2026
A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and external resources available through the network or filesystem.…
AnalizadaMedia (4.3)0.66%💥 ExploitWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+230/5/202517/6/2026
An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper authorization.…
ModificadaMedia (5.4)0.71%—Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+230/5/202517/6/2026
Exploiting this vulnerability allows malicious actors to assign higher privileges to self-registered users, bypassing intended access control mechanisms.
AnalizadaCrítica (9.8)0.72%—Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+222/5/202517/6/2026
An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exploit this vulnerability to reset the password of any user account, leading to a complete account takeover, including accounts with elevated…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server Analytics+418/4/202217/6/2026
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects…
Orbitaley — Vulnerabilidades