Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

78 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.6%—EMC RSA Certificate Manager3/7/201817/6/2026
RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server. A remote unauthenticated attacker could potentially exploit this vulnerability by manipulating input parameters of the application to gain…
ModificadaMedia (6.1)0.71%—Bobcares Gift-certificate-creator14/9/201717/6/2026
Vulnerability in wordpress plugin gift-certificate-creator v1.0, The code in gc-list.php doesn't sanitize user input to prevent a stored XSS vulnerability.
ModificadaAlta (7.8)3.2%—EMC RSA Certificate ManagerEMC RSA Onestep2/10/201517/6/2026
Directory traversal vulnerability in EMC RSA OneStep 6.9 before build 559, as used in RSA Certificate Manager and RSA Registration Manager through 6.9 build 558 and other products, allows remote attackers to read arbitrary files via a crafted KCSOSC_ERROR_PAGE parameter.
ModificadaAlta (7.8)2.3%—EMC RSA Certificate ManagerEMC RSA Registration Manager12/3/201517/6/2026
EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allow remote attackers to cause an Administration Server denial of service via an invalid MIME e-mail message with a multipart/* Content-Type header.
ModificadaMedia (4.3)1.2%—EMC RSA Certificate ManagerEMC RSA Registration Manager12/3/201517/6/2026
Cross-site scripting (XSS) vulnerability in EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allows remote attackers to inject arbitrary web script or HTML via vectors related to the email address parameter.
ModificadaBaja (3.5)0.94%—EMC RSA Certificate ManagerEMC RSA Registration Manager12/3/201517/6/2026
Cross-site scripting (XSS) vulnerability in EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the CMP shared secret parameter.
ModificadaAlta (7.5)2.2%—Redhat Certificate SystemRedhat Dogtag Certificate System24/1/201416/6/2026
Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors,…
ModificadaMedia (4.3)1.2%—Redhat Certificate SystemRedhat Dogtag Certificate System24/1/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) tus/ or (2) tus/tus/.
ModificadaMedia (4)1.2%—Redhat Certificate System4/1/201316/6/2026
The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause a denial of service (Apache httpd web server child process restart) via certain unspecified empty search fields in a user certificate search query.
ModificadaMedia (4)1.2%—Redhat Certificate System4/1/201316/6/2026
The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interruptions of token format operations, which allows remote attackers to cause a denial of service (NULL pointer dereference and Apache httpd web server child process crash) via unspecified vectors.
ModificadaMedia (4.3)1.2%—Redhat Certificate System4/1/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) pageStart or (2) pageSize to the displayCRL script, or (3) nonce variable to the profileProcess script.
ModificadaMedia (5.5)1.2%—Redhat Certificate SystemRedhat Dogtag Certificate System13/8/201216/6/2026
Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revoke end entity certificates to revoke the Certificate Authority (CA) certificate.
ModificadaMedia (4.3)1.4%—Redhat Certificate SystemRedhat Dogtag Certificate System13/8/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to the (1) System Agent or (2) End Entity pages.
ModificadaMedia (4)0.78%—Redhat Certificate SystemRedhat Dogtag Certificate System17/11/201016/6/2026
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System allow remote authenticated users to generate an arbitrary number of certificates by replaying a single SCEP one-time PIN.
ModificadaMedia (5.8)1.3%—Redhat Certificate SystemRedhat Dogtag Certificate System17/11/201016/6/2026
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.
ModificadaMedia (6.5)1.3%—Redhat Certificate SystemRedhat Dogtag Certificate System27/5/200916/6/2026
agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.
ModificadaMedia (6)0.78%—Redhat Dogtag Certificate SystemRedhat Certificate System30/1/200916/6/2026
The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use the hardware key, which allows remote authenticated users with enrollment privileges to bypass…
ModificadaBaja (2.1)0.24%—Redhat Certificate System20/1/200916/6/2026
Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files.
ModificadaBaja (2.1)0.24%—Redhat Certificate System20/1/200916/6/2026
Red Hat Certificate System 7.2 uses world-readable permissions for password.conf and unspecified other configuration files, which allows local users to discover passwords by reading these files.
ModificadaAlta (7.5)1.1%—Netscape Certificate Management System7/7/200816/6/2026
Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not recognize Certificate Authority profile constraints on Extensions, which might allow remote attackers to bypass intended restrictions and…
ModificadaAlta (7.5)1.1%—Redhat Certificate Server6/11/200716/6/2026
Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (CRL) is being generated, which might prevent certain revoked certificates from appearing on the CRL quickly and allow users with revoked certificates to bypass the…
ModificadaBaja (3.6)0.21%—RSA Keon Certificate Authority Manager26/9/200616/6/2026
RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 and 6.6 allows privileged local users to hide malicious Certificate Authority (CA) activities by modifying CA auditor logs without detection by (1) modifying or deleting a <LOG BLOCK> and its signature from the XML log in a way that is not detected by the integrity…
ModificadaAlta (7.5)23%—Mozilla Network Security ServicesNetscape Certificate ServerNetscape Directory ServerNetscape Enterprise Server+631/12/200416/6/2026
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.
ModificadaMedia (5.1)0.87%—SUN Security CertificatesAI12/2/200116/6/2026
Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun.
ModificadaMedia (5)6.0%💥 ExploitNetscape Directory ServerSUN Iplanet Certificate Management System11/12/200016/6/2026
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.
Orbitaley — Vulnerabilidades