Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
944 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.27% | — | IBM Verify Identity AccessAI | 15/9/2026 | 19/9/2026 | IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests. | |
| Pendiente de análisis | Media (6.5) | 0.17% | — | IBM Security Verify Identity AccessAI | 15/9/2026 | 19/9/2026 | IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services. | |
| Pendiente de análisis | Media (4.7) | 0.28% | — | IBM Verify Identity AccessAI | 14/9/2026 | 16/9/2026 | IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear… | |
| Pendiente de análisis | Media (6.1) | 0.24% | — | IBM Verify Identity AccessAIIBM Security Verify AccessAIIBM Verify Identity Access ContainerAIIBM Security Verify Access ContainerAI | 14/9/2026 | 16/9/2026 | IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001. | |
| Pendiente de análisis | Alta (7.5) | 0.43% | — | IBM Verify Identity AccessAI | 14/9/2026 | 16/9/2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | |
| Pendiente de análisis | Alta (8.6) | 0.69% | — | TeamAIAmazon IAM Identity CenterAI | 14/9/2026 | 14/9/2026 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated… | |
| Pendiente de análisis | Media (5.4) | 0.15% | — | IBM Verify Identity AccessAI | 14/9/2026 | 19/9/2026 | IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems. | |
| Pendiente de análisis | Alta (7.5) | 0.25% | — | IBM Verify Identity Access Advanced Access ControlAI | 4/9/2026 | 8/9/2026 | IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack. | |
| Analizada | Alta (8.4) | 0.22% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 3/9/2026 | 9/9/2026 | The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon… | |
| Pendiente de análisis | Media (6.5) | 0.32% | — | Apache HttpdAIDogtag Certificate AuthorityAIRedhat Identity ManagementAI | 1/9/2026 | 1/9/2026 | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion… | |
| Modificada | Alta (7.8) | 0.16% | — | Oracle Identity Manager | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager executes to… | |
| Modificada | Alta (8.8) | 0.43% | — | Oracle Identity Manager | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful… | |
| Modificada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via RMI to compromise Oracle Identity Manager. While the… | |
| Modificada | Alta (8) | 0.38% | — | Oracle Identity Manager Connector | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle… | |
| Analizada | Alta (8.7) | 0.41% | — | Oracle Identity Manager Connector | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Connectors and Connector Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager Connector | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Identity Manager Connector.… | |
| Analizada | Alta (7.2) | 0.12% | — | Oracle Identity Manager Connector | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager Connector… | |
| Modificada | Alta (7.5) | 0.33% | — | Oracle Identity Manager Connector | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware… | |
| Modificada | Alta (8.1) | 0.39% | — | Oracle Identity Manager Connector | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Identity Manager… | |
| Modificada | Alta (7.8) | 0.16% | — | Oracle Identity Manager Connector | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager Connector… | |
| Modificada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager Connector | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Identity Manager Connector.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Identity Manager | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.… | |
| Modificada | Alta (8.8) | 0.43% | — | Oracle Identity Manager | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager.… | |
| Modificada | Crítica (9.8) | 0.51% | — | Oracle Identity Manager | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.… | |
| Modificada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the… |