Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.3% | — | Wso2 API ManagerWso2 Identity Server | 28/1/2020 | 17/6/2026 | An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. When a custom claim dialect with an XSS payload is configured in the identity provider basic claim configuration, that payload gets executed, if a user picks up that dialect's URI as the provisioning claim… | |
| Modificada | Media (6.1) | 1.4% | — | Wso2 API ManagerWso2 Identity Server | 28/1/2020 | 17/6/2026 | An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. If there is a claim dialect configured with an XSS payload in the dialect URI, and a user picks up this dialect's URI and adds it as the service provider claim dialect while configuring the service… | |
| Modificada | Media (4.8) | 0.80% | — | Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server | 28/1/2020 | 17/6/2026 | An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI. | |
| Modificada | Media (4.8) | 0.73% | — | Wso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server | 28/1/2020 | 17/6/2026 | An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI. | |
| Modificada | Media (6.1) | 0.64% | — | Wso2 Identity Server | 12/11/2019 | 17/6/2026 | WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled. | |
| Modificada | Media (6.1) | 0.74% | — | Wso2 Identity Server | 12/11/2019 | 17/6/2026 | WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile. | |
| Modificada | Media (5.4) | 0.98% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager | 21/3/2019 | 17/6/2026 | An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product. | |
| Modificada | Media (5.4) | 38% | 💥 Exploit | Wso2 Identity Server | 25/4/2018 | 17/6/2026 | WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers. | |
| Modificada | Media (4.8) | 3.8% | 💥 Exploit | Wso2 API ManagerWso2 APP ManagerWso2 Application ServerWso2 Business Process Server+13 | 21/9/2017 | 17/6/2026 | WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter. | |
| Modificada | Alta (7.5) | 6.0% | 💥 Exploit | Wso2 Identity Server | 17/2/2017 | 17/6/2026 | XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to XACML features to read arbitrary files, cause a denial of service, conduct server-side request forgery (SSRF) attacks, or have unspecified… | |
| Modificada | Alta (8.8) | 3.4% | 💥 Exploit | Wso2 Identity Server | 17/2/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request. | |
| Modificada | Media (6.8) | 2.2% | — | SUN Java System Identity Server | 14/1/2010 | 16/6/2026 | Unspecified vulnerability in Sun Java System Identity Manager (aka IdM) 8.1.0.5 and 8.1.0.6, when Sun Java System Access Manager, OpenSSO Enterprise 8.0, or IBM Tivoli Access Manager is used, allows remote attackers to obtain administrative access via unknown vectors. | |
| Modificada | Alta (7.5) | 2.8% | — | SUN Java System Access ManagerSUN Java System Identity Server | 30/6/2008 | 16/6/2026 | Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and… | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Novell Access Manager Identity Server | 9/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject arbitrary web script or HTML via the IssueInstant parameter, which is not properly handled in the resulting error message. |