Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.6% | — | EMC RSA Certificate Manager | 3/7/2018 | 17/6/2026 | RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server. A remote unauthenticated attacker could potentially exploit this vulnerability by manipulating input parameters of the application to gain… | |
| Modificada | Media (6.1) | 0.71% | — | Bobcares Gift-certificate-creator | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin gift-certificate-creator v1.0, The code in gc-list.php doesn't sanitize user input to prevent a stored XSS vulnerability. | |
| Modificada | Alta (7.8) | 3.2% | — | EMC RSA Certificate ManagerEMC RSA Onestep | 2/10/2015 | 17/6/2026 | Directory traversal vulnerability in EMC RSA OneStep 6.9 before build 559, as used in RSA Certificate Manager and RSA Registration Manager through 6.9 build 558 and other products, allows remote attackers to read arbitrary files via a crafted KCSOSC_ERROR_PAGE parameter. | |
| Modificada | Alta (7.8) | 2.3% | — | EMC RSA Certificate ManagerEMC RSA Registration Manager | 12/3/2015 | 17/6/2026 | EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allow remote attackers to cause an Administration Server denial of service via an invalid MIME e-mail message with a multipart/* Content-Type header. | |
| Modificada | Media (4.3) | 1.2% | — | EMC RSA Certificate ManagerEMC RSA Registration Manager | 12/3/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allows remote attackers to inject arbitrary web script or HTML via vectors related to the email address parameter. | |
| Modificada | Baja (3.5) | 0.94% | — | EMC RSA Certificate ManagerEMC RSA Registration Manager | 12/3/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the CMP shared secret parameter. | |
| Modificada | Alta (7.5) | 2.2% | — | Redhat Certificate SystemRedhat Dogtag Certificate System | 24/1/2014 | 16/6/2026 | Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors,… | |
| Modificada | Media (4.3) | 1.2% | — | Redhat Certificate SystemRedhat Dogtag Certificate System | 24/1/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) tus/ or (2) tus/tus/. | |
| Modificada | Media (4) | 1.2% | — | Redhat Certificate System | 4/1/2013 | 16/6/2026 | The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause a denial of service (Apache httpd web server child process restart) via certain unspecified empty search fields in a user certificate search query. | |
| Modificada | Media (4) | 1.2% | — | Redhat Certificate System | 4/1/2013 | 16/6/2026 | The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interruptions of token format operations, which allows remote attackers to cause a denial of service (NULL pointer dereference and Apache httpd web server child process crash) via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Redhat Certificate System | 4/1/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) pageStart or (2) pageSize to the displayCRL script, or (3) nonce variable to the profileProcess script. | |
| Modificada | Media (5.5) | 1.2% | — | Redhat Certificate SystemRedhat Dogtag Certificate System | 13/8/2012 | 16/6/2026 | Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revoke end entity certificates to revoke the Certificate Authority (CA) certificate. | |
| Modificada | Media (4.3) | 1.4% | — | Redhat Certificate SystemRedhat Dogtag Certificate System | 13/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to the (1) System Agent or (2) End Entity pages. | |
| Modificada | Media (4) | 0.78% | — | Redhat Certificate SystemRedhat Dogtag Certificate System | 17/11/2010 | 16/6/2026 | Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System allow remote authenticated users to generate an arbitrary number of certificates by replaying a single SCEP one-time PIN. | |
| Modificada | Media (5.8) | 1.3% | — | Redhat Certificate SystemRedhat Dogtag Certificate System | 17/11/2010 | 16/6/2026 | Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component. | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Certificate SystemRedhat Dogtag Certificate System | 27/5/2009 | 16/6/2026 | agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field. | |
| Modificada | Media (6) | 0.78% | — | Redhat Dogtag Certificate SystemRedhat Certificate System | 30/1/2009 | 16/6/2026 | The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use the hardware key, which allows remote authenticated users with enrollment privileges to bypass… | |
| Modificada | Baja (2.1) | 0.24% | — | Redhat Certificate System | 20/1/2009 | 16/6/2026 | Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files. | |
| Modificada | Baja (2.1) | 0.24% | — | Redhat Certificate System | 20/1/2009 | 16/6/2026 | Red Hat Certificate System 7.2 uses world-readable permissions for password.conf and unspecified other configuration files, which allows local users to discover passwords by reading these files. | |
| Modificada | Alta (7.5) | 1.1% | — | Netscape Certificate Management System | 7/7/2008 | 16/6/2026 | Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not recognize Certificate Authority profile constraints on Extensions, which might allow remote attackers to bypass intended restrictions and… | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Certificate Server | 6/11/2007 | 16/6/2026 | Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (CRL) is being generated, which might prevent certain revoked certificates from appearing on the CRL quickly and allow users with revoked certificates to bypass the… | |
| Modificada | Baja (3.6) | 0.21% | — | RSA Keon Certificate Authority Manager | 26/9/2006 | 16/6/2026 | RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 and 6.6 allows privileged local users to hide malicious Certificate Authority (CA) activities by modifying CA auditor logs without detection by (1) modifying or deleting a <LOG BLOCK> and its signature from the XML log in a way that is not detected by the integrity… | |
| Modificada | Alta (7.5) | 23% | — | Mozilla Network Security ServicesNetscape Certificate ServerNetscape Directory ServerNetscape Enterprise Server+6 | 31/12/2004 | 16/6/2026 | Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message. | |
| Modificada | Media (5.1) | 0.87% | — | SUN Security CertificatesAI | 12/2/2001 | 16/6/2026 | Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun. | |
| Modificada | Media (5) | 6.0% | 💥 Exploit | Netscape Directory ServerSUN Iplanet Certificate Management System | 11/12/2000 | 16/6/2026 | Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services. |