Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

91 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.54%—Esafenet CDG17/10/202417/6/2026
A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of the file /com/esafenet/policy/action/PolicyPushControlAction.java. The manipulation of the argument policyId leads to sql injection. It is possible to initiate the attack remotely. The exploit has…
AnalizadaMedia (5.3)0.54%—Esafenet CDG17/10/202417/6/2026
A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function actionPassMainApplication of the file /com/esafenet/servlet/client/MailDecryptApplicationService.java. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The…
AnalizadaMedia (5.3)0.66%—Esafenet CDG6/10/202417/6/2026
A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is the function delCatelogs of the file /CDGServer3/document/Catelogs;logindojojs?command=DelCatelogs. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has…
AnalizadaMedia (5.3)0.64%—Esafenet CDG5/10/202417/6/2026
A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /MultiServerBackService?path=1. The manipulation of the argument fileId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public…
AnalizadaAlta (7.6)0.35%—Esafenet CDG30/9/202417/6/2026
ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax interface
AnalizadaCrítica (9.1)0.63%—Esafenet CDG5/9/202417/6/2026
SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.
AnalizadaAlta (7.8)0.34%💥 PoCThalesgroup Safenet Authentication Client27/2/202417/6/2026
A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access.
AnalizadaAlta (7.8)0.17%—Thalesgroup Safenet Authentication Client27/2/202417/6/2026
A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access.
ModificadaMedia (5.5)0.14%—Thalesgroup Safenet Authentication Service16/8/202317/6/2026
Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via local privilege escalation.
ModificadaMedia (6.7)1.0%💥 PoCThalesgroup Safenet Authentication Client24/6/202217/6/2026
Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, to overwrite arbitrary files, and potentially achieve arbitrary command execution with high privileges.
ModificadaMedia (6.5)0.53%—Thalesgroup Safenet Keysecure10/6/202217/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows an authenticated user to read arbitrary files from the underlying system on which the product is deployed.
ModificadaAlta (7.8)0.32%—Thalesgroup Safenet Authentication Service Remote Desktop Gateway19/1/202217/6/2026
A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed.
ModificadaMedia (6.5)0.58%—Thalesgroup Safenet Windows Logon Agent20/12/202117/6/2026
A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted credentials of any or all the users on that machine.
ModificadaMedia (6.5)1.2%—Thalesgroup Safenet Keysecure16/6/20219/7/2026
SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked.
ModificadaAlta (7.5)2.1%—Esafenet CDG30/9/201917/6/2026
CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal.
ModificadaAlta (7.5)40%💥 ExploitEsafenet Electronic Document Security Management System8/3/201917/6/2026
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service FOR Citrix WEB Interface Agent2/3/201817/6/2026
SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service Windows Logon Agent2/3/201817/6/2026
SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7965.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service Windows Logon Agent2/3/201817/6/2026
SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7966.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service FOR NPS Agent2/3/201817/6/2026
SafeNet Authentication Service for NPS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service FOR AD FS Agent2/3/201817/6/2026
SafeNet Authentication Service for AD FS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.8)0.41%—Gemalto Safenet Authentication Service FOR Outlook WEB APP Agent2/3/201817/6/2026
SafeNet Authentication Service for Outlook Web App Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service Remote WEB Workplace Agent2/3/201817/6/2026
SafeNet Authentication Service Remote Web Workplace Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service Tokenvalidator Proxy Agent2/3/201817/6/2026
SafeNet Authentication Service TokenValidator Proxy Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service IIS Agent2/3/201817/6/2026
SafeNet Authentication Service IIS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
Orbitaley — Vulnerabilidades