Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
944 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Identity Manager | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Identity Manager | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.… | |
| Modificada | Crítica (9.1) | 0.43% | — | Oracle Identity Manager | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Identity Manager | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager.… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Identity Manager Connector | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Identity Manager Connector | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (7.7) | 0.33% | — | Oracle Identity Manager Connector | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8) | 0.29% | — | Oracle Identity Manager Connector | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Identity Manager Connector | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager Connector | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager Connector.… | |
| Analizada | Alta (8.5) | 0.33% | — | Oracle Identity Manager | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Identity Manager | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Identity Manager.… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Identity Manager | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful… | |
| Analizada | Crítica (9.8) | 0.40% | — | Sailpoint Identityiq | 20/7/2026 | 30/7/2026 | This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens. | |
| Aplazada | Alta (7.1) | 0.27% | — | Syslog-ngAIBalabit Syslog-ng Premium EditionAIOneidentity Syslog-ng Store BOXAI | 20/7/2026 | 23/7/2026 | Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver… | |
| Analizada | Media (6.1) | 0.25% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity Server | 20/7/2026 | 19/8/2026 | The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacker can leverage this vulnerability to cause the user's browser to… | |
| Analizada | Media (5.3) | 0.40% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 17/7/2026 | 11/8/2026 | IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Media (6.1) | 0.36% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 17/7/2026 | 30/7/2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect… | |
| Analizada | Media (6.5) | 0.30% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 17/7/2026 | 30/7/2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow an attacker with read-only privileges to make unauthorized modifications and… | |
| Analizada | Media (5.5) | 0.50% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 15/7/2026 | 25/9/2026 | This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system. | |
| Aplazada | Media (5.3) | 0.46% | — | Token OF Trust AGE Verification Identity VerificationAI | 9/7/2026 | 9/7/2026 | The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and including 4.0.2. This is due to the handle_export_table() function being registered on the WordPress 'init' hook, which fires for all requests, including those from… | |
| Pendiente de análisis | Alta (8.8) | 0.49% | — | 389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI | 7/7/2026 | 8/7/2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds… | |
| Analizada | Media (6.1) | 0.25% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/7/2026 | 6/10/2026 | The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser… | |
| Analizada | Media (5.3) | 0.30% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+1 | 4/7/2026 | 9/7/2026 | The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to… | |
| Analizada | Alta (7.3) | 0.27% | — | Wso2 API ManagerWso2 Identity Server | 4/7/2026 | 6/10/2026 | In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS applications with the same name in other tenants, leading to unintended… |