Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.36% | — | Armiya Information Technologies LTD Access Control SystemAI | 10/9/2026 | 10/9/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Armiya Information Technologies LTD Access Control SystemAI | 10/9/2026 | 10/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Control System: before Versiyon 2. | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | Paloaltonetworks Prisma Access AgentAI | 10/9/2026 | 10/9/2026 | A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected. | |
| Pendiente de análisis | Media (4.3) | 0.10% | — | Paloaltonetworks Prisma Access AgentAI | 10/9/2026 | 10/9/2026 | An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected. | |
| Aplazada | Media (6.1) | 0.21% | — | User Access ManagerAI | 9/9/2026 | 11/9/2026 | The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section' parameter in all versions up to, and including, 2.3.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Pendiente de análisis | Media (5) | 0.20% | — | Okta Privileged Access ClientAIOkta ScaleftAI | 8/9/2026 | 10/9/2026 | The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended… | |
| Analizada | Media (6.7) | 0.22% | — | Okta Access Gateway | 8/9/2026 | 22/9/2026 | The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated local user with access to the management interface can supply crafted values, resulting in the execution of arbitrary OS commands with root… | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2016Microsoft Office 2019+2 | 8/9/2026 | 10/9/2026 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+1 | 8/9/2026 | 10/9/2026 | Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2016Microsoft Office 2019+2 | 8/9/2026 | 10/9/2026 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.3) | 0.43% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+1 | 8/9/2026 | 10/9/2026 | Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally. | |
| Analizada | Media (6.5) | 0.36% | — | Okta Access Gateway | 8/9/2026 | 22/9/2026 | The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources. | |
| Analizada | Media (6.7) | 0.23% | — | Okta Access Gateway | 8/9/2026 | 22/9/2026 | The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the privileges of the web server process. | |
| Analizada | Media (4.9) | 0.46% | — | Okta Access Gateway | 8/9/2026 | 22/9/2026 | The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem. | |
| Analizada | Crítica (9.9) | 0.45% | — | Okta Access Gateway | 8/9/2026 | 22/9/2026 | The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to preparation, resulting in unintended SQL execution against the configured backend… | |
| Analizada | Media (4.9) | 0.34% | — | Okta Access Gateway | 8/9/2026 | 22/9/2026 | The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file contents. The path from the event payload is used directly as the write destination, resulting in files being written to unintended locations on the appliance filesystem. | |
| Analizada | Media (6.5) | 0.24% | — | Okta Access Gateway | 8/9/2026 | 23/9/2026 | The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic. | |
| Analizada | Media (6.5) | 0.20% | — | Okta Access Gateway | 8/9/2026 | 23/9/2026 | The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where this optional source is enabled without an upstream reverse proxy or firewall configured to sanitize and enforce client… | |
| Analizada | Media (4.9) | 0.27% | — | Okta Access Gateway | 8/9/2026 | 23/9/2026 | The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives. | |
| Analizada | Alta (7.2) | 0.38% | — | Okta Access Gateway | 8/9/2026 | 29/9/2026 | The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution with the privileges of the management console. | |
| Analizada | Alta (7.2) | 0.38% | — | Okta Access Gateway | 8/9/2026 | 29/9/2026 | The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives. | |
| Pendiente de análisis | Alta (7.5) | 0.25% | — | IBM Verify Identity Access Advanced Access ControlAI | 4/9/2026 | 8/9/2026 | IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack. | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Aplazada | Media (5.3) | 0.35% | — | Dev.institute Restrict User AccessAI | 2/9/2026 | 3/9/2026 | The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users. | |
| Pendiente de análisis | Alta (8.8) | 1.4% | — | Zoho Password Manager PROAIZoho Pam360AIZoho Access Manager PlusAI | 2/9/2026 | 8/9/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability. |