Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8) | 0.38% | — | Opentext Privileged Access ManagerAI | 19/12/2024 | 17/6/2026 | In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5) | |
| Aplazada | Media (6.5) | 0.50% | — | Prism IT Systems User Rights Access ManagerAI | 1/11/2024 | 17/6/2026 | Access Control vulnerability in Prism IT Systems User Rights Access Manager allows . This issue affects User Rights Access Manager: from n/a through 1.1.2. | |
| Analizada | Alta (7.5) | 2.8% | 💥 Exploit | Vasyltech Advanced Access Manager | 16/10/2024 | 17/6/2026 | The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php | |
| Analizada | Alta (7.5) | 0.43% | — | Microfocus Netiq Access Manager | 28/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Manager allows access the sensitive information. This issue affects NetIQ Access Manager before 5.0.4 and before 5.1. | |
| Modificada | Alta (7.5) | 0.27% | — | Microfocus Netiq Access Manager | 28/8/2024 | 17/6/2026 | Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and before 5.1 | |
| Modificada | Media (5.4) | 0.29% | — | Microfocus Netiq Access Manager | 28/8/2024 | 17/6/2026 | Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. This issue affects Access Manager before 5.0.4.1 and 5.1. | |
| Analizada | Alta (7.8) | 0.31% | — | Microfocus Netiq Privileged Access Manager | 21/8/2024 | 17/6/2026 | SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1. | |
| Analizada | Alta (7.5) | 0.33% | — | Microfocus Netiq Privileged Access Manager | 21/8/2024 | 17/6/2026 | A vulnerability found in OpenText Privileged Access Manager that issues a token. on successful issuance of the token, a cookie gets set that allows unrestricted access to all the application resources. This issue affects Privileged Access Manager before 3.7.0.1. | |
| Modificada | Media (5.5) | 0.23% | — | IBM Security Access Manager | 28/6/2024 | 17/6/2026 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415. | |
| Modificada | Media (6.2) | 0.26% | — | IBM Security Access Manager | 28/6/2024 | 17/6/2026 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413. | |
| Modificada | Media (6.5) | 0.70% | — | IBM Security Access Manager | 27/6/2024 | 17/6/2026 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197. | |
| Modificada | Media (5.5) | 0.19% | — | IBM Security Access Manager | 27/6/2024 | 17/6/2026 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls. IBM X-Force ID: 261195. | |
| Modificada | Alta (7.8) | 0.23% | — | IBM Security Access Manager | 27/6/2024 | 17/6/2026 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254649. | |
| Modificada | Alta (7.8) | 0.23% | — | IBM Security Access Manager | 27/6/2024 | 17/6/2026 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254638. | |
| Modificada | Alta (7.5) | 0.46% | — | IBM Security Access Manager | 27/6/2024 | 17/6/2026 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 261198. | |
| Modificada | Media (6.5) | 0.48% | — | Netiq Access Manager | 11/6/2024 | 17/6/2026 | This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before | |
| Aplazada | Media (5.8) | 0.31% | — | Prism IT Systems User Rights Access ManagerAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism IT Systems User Rights Access Manager allows Reflected XSS.This issue affects User Rights Access Manager: from n/a through 1.1.2. | |
| Modificada | Media (6.5) | 0.45% | — | Seling Visual Access Manager | 19/3/2024 | 17/6/2026 | An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific reception by POST HTTP request interception. Iterating that parameter, it has been possible to access to the application and take control of many other receptions in… | |
| Aplazada | Media (5.9) | 0.38% | — | Vasyltech Advanced Access ManagerAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Stored XSS.This issue affects Advanced Access Manager: from n/a through 6.9.20. | |
| Modificada | Media (6.1) | 0.44% | — | Vasyltech Advanced Access Manager | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Reflected XSS.This issue affects Advanced Access Manager: from n/a through 6.9.20. | |
| Modificada | Alta (7.5) | 0.53% | — | IBM Security Access Manager Container | 7/2/2024 | 17/6/2026 | IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 does not require that docker images should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 261196. | |
| Modificada | Media (5.5) | 0.13% | — | IBM Security Access Manager Container | 7/2/2024 | 17/6/2026 | IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657. | |
| Modificada | Media (5.4) | 0.33% | — | Vasyltech Advanced Access Manager | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More:… | |
| Modificada | Alta (7.5) | 0.44% | — | Wallix BastionWallix Bastion Access Manager | 8/1/2024 | 17/6/2026 | WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure. | |
| Modificada | Media (5.4) | 0.30% | — | Vasyltech Advanced Access Manager | 29/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.18. |