Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

2624 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.36%—Armiya Information Technologies LTD Access Control SystemAI10/9/202610/9/2026
URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.
AplazadaCrítica (9.8)0.47%—Armiya Information Technologies LTD Access Control SystemAI10/9/202610/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Control System: before Versiyon 2.
Pendiente de análisisMedia (5.8)0.10%—Paloaltonetworks Prisma Access AgentAI10/9/202610/9/2026
A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.
Pendiente de análisisMedia (4.3)0.10%—Paloaltonetworks Prisma Access AgentAI10/9/202610/9/2026
An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected.
AplazadaMedia (6.1)0.21%—User Access ManagerAI9/9/202611/9/2026
The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section' parameter in all versions up to, and including, 2.3.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
Pendiente de análisisMedia (5)0.20%—Okta Privileged Access ClientAIOkta ScaleftAI8/9/202610/9/2026
The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended…
AnalizadaMedia (6.7)0.22%—Okta Access Gateway8/9/202622/9/2026
The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated local user with access to the management interface can supply crafted values, resulting in the execution of arbitrary OS commands with root…
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2016Microsoft Office 2019+28/9/202610/9/2026
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.86%—Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+18/9/202610/9/2026
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2016Microsoft Office 2019+28/9/202610/9/2026
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.3)0.43%—Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+18/9/202610/9/2026
Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
AnalizadaMedia (6.5)0.36%—Okta Access Gateway8/9/202622/9/2026
The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
AnalizadaMedia (6.7)0.23%—Okta Access Gateway8/9/202622/9/2026
The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the privileges of the web server process.
AnalizadaMedia (4.9)0.46%—Okta Access Gateway8/9/202622/9/2026
The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.
AnalizadaCrítica (9.9)0.45%—Okta Access Gateway8/9/202622/9/2026
The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to preparation, resulting in unintended SQL execution against the configured backend…
AnalizadaMedia (4.9)0.34%—Okta Access Gateway8/9/202622/9/2026
The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file contents. The path from the event payload is used directly as the write destination, resulting in files being written to unintended locations on the appliance filesystem.
AnalizadaMedia (6.5)0.24%—Okta Access Gateway8/9/202623/9/2026
The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic.
AnalizadaMedia (6.5)0.20%—Okta Access Gateway8/9/202623/9/2026
The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where this optional source is enabled without an upstream reverse proxy or firewall configured to sanitize and enforce client…
AnalizadaMedia (4.9)0.27%—Okta Access Gateway8/9/202623/9/2026
The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.
AnalizadaAlta (7.2)0.38%—Okta Access Gateway8/9/202629/9/2026
The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution with the privileges of the management console.
AnalizadaAlta (7.2)0.38%—Okta Access Gateway8/9/202629/9/2026
The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.
Pendiente de análisisAlta (7.5)0.25%—IBM Verify Identity Access Advanced Access ControlAI4/9/20268/9/2026
IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.
AnalizadaBaja (2.3)0.23%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+172/9/202615/9/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.…
AplazadaMedia (5.3)0.35%—Dev.institute Restrict User AccessAI2/9/20263/9/2026
The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.
Pendiente de análisisAlta (8.8)1.4%—Zoho Password Manager PROAIZoho Pam360AIZoho Access Manager PlusAI2/9/20268/9/2026
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
Orbitaley — Vulnerabilidades