Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
944 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.43% | — | Oracle Identity Manager | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Identity Manager | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful… | |
| Analizada | Alta (8.7) | 0.41% | — | Oracle Identity Manager | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the… | |
| Analizada | Crítica (9.8) | 0.40% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 18/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnerable to a denial of service attack. | |
| Analizada | Alta (8.1) | 0.35% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request. | |
| Analizada | Alta (7.2) | 0.54% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input. | |
| Analizada | Alta (8.1) | 0.45% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy. | |
| Analizada | Alta (7.2) | 0.54% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a… | |
| Analizada | Alta (8.7) | 0.49% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface that allows attackers to cause denial of service and information disclosure by… | |
| Analizada | Baja (3.1) | 0.29% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 Reverse Proxy in certain configurations is vulnerable to a denial of service attack. | |
| Analizada | Alta (7.4) | 0.32% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Aplazada | Media (4.9) | 0.21% | — | Pingidentity PingfederateAI | 10/8/2026 | 29/9/2026 | Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions. | |
| Analizada | Media (4.4) | 0.16% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/8/2026 | 12/8/2026 | When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such… | |
| Analizada | Media (4.9) | 0.19% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/8/2026 | 13/8/2026 | Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client… | |
| Analizada | Alta (7.5) | 0.41% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/8/2026 | 9/8/2026 | The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the… | |
| En análisis | Media (5.8) | 0.29% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+3 | 6/8/2026 | 9/8/2026 | The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidated input into user claims can lead to various security risks. Malicious… | |
| Analizada | Crítica (9.4) | 0.67% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+5 | 6/8/2026 | 29/9/2026 | The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how… | |
| Analizada | Baja (3.8) | 0.32% | — | Wso2 Identity Server | 6/8/2026 | 29/9/2026 | The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associated with that type across all organizations. Exploitation of this vulnerability… | |
| Analizada | Media (4.3) | 0.35% | — | Wso2 Identity Server | 6/8/2026 | 29/9/2026 | The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful… | |
| Analizada | Baja (3.7) | 0.27% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+1 | 6/8/2026 | 29/9/2026 | When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original input. This occurs regardless of the validate_username configuration.… | |
| Analizada | Media (5.4) | 0.14% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 6/8/2026 | 29/9/2026 | The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie attribute is employed for mitigation, this mechanism is bypassed as it… | |
| Analizada | Baja (2.4) | 0.20% | — | Wso2 Identity Server | 6/8/2026 | 29/9/2026 | The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant to obtain new access tokens, extending their ability to act as the… | |
| Analizada | Media (4.3) | 0.31% | — | Wso2 Identity Server | 6/8/2026 | 29/9/2026 | When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and bypasses the primary user store during search and uniqueness checks. This allows a subject to be associated with an unintended local account if the same lookup claim (e.g., username or… | |
| Analizada | Media (5.3) | 0.40% | — | IBM Verify Identity AccessIBM Verify Identity Access Container | 30/7/2026 | 12/8/2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error… |