Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.24% | — | Microfocus Access Manager | 2/9/2021 | 17/6/2026 | This release addresses a potential information leakage vulnerability in NetIQ Access Manager versions prior to 5.0.1 | |
| Modificada | Media (4.9) | 1.6% | — | Oracle Access Manager | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Rest interfaces for Access Mgr). The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Access Manager.… | |
| Modificada | Alta (7.5) | 1.2% | — | IBM Security Access ManagerIBM Security Verify Access | 15/7/2021 | 17/6/2026 | IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user. | |
| Modificada | Media (4.8) | 9.9% | 💥 PoC | Apache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+56 | 13/4/2021 | 25/8/2026 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling… | |
| Analizada | Alta (7.5) | 26% | ⚠ Explotación activa | Microfocus Access Manager | 26/3/2021 | 17/6/2026 | Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause information leakage. | |
| Modificada | Media (6.1) | 0.61% | — | Microfocus Access Manager | 26/3/2021 | 17/6/2026 | Cross-Site scripting vulnerability in Micro Focus Access Manager product, affects all version prior to version 5.0. The vulnerability could cause configuration destruction. | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Access Manager | 25/3/2021 | 17/6/2026 | Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage. | |
| Modificada | Alta (8.3) | 1.4% | — | Oracle Advanced Networking OptionOracle Adaptive Access ManagerOracle Data IntegratorOracle Enterprise Manager FOR Fusion Applications+2 | 20/1/2021 | 17/6/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human… | |
| Modificada | Alta (8.8) | 1.5% | — | Vasyltech Advanced Access Manager | 1/1/2021 | 17/6/2026 | The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism for deciding whether a user was entitled to add a role did not work in various custom-role scenarios.) | |
| Modificada | Media (4.3) | 1.1% | — | Vasyltech Advanced Access Manager | 1/1/2021 | 17/6/2026 | The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metadata… | |
| Modificada | Crítica (9.8) | 1.2% | — | IBM Security Access ManagerIBM Security Verify Access | 15/10/2020 | 17/6/2026 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216. | |
| Modificada | Media (6.1) | 0.92% | — | IBM Security Access ManagerIBM Security Verify Access | 15/10/2020 | 17/6/2026 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform… | |
| Modificada | Media (5.4) | 0.56% | — | IBM Security Access Manager Appliance | 14/10/2020 | 17/6/2026 | IBM Security Access Manager Appliance 9.0.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 179358. | |
| Modificada | Media (5.3) | 0.46% | — | IBM Security Access ManagerIBM Security Verify Access | 12/10/2020 | 17/6/2026 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186947. | |
| Modificada | Media (5.3) | 0.46% | — | IBM Security Access ManagerIBM Security Verify Access | 12/10/2020 | 17/6/2026 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186142. | |
| Modificada | Media (5.3) | 0.46% | — | IBM Security Access ManagerIBM Security Verify Access | 12/10/2020 | 17/6/2026 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186140. | |
| Modificada | Media (6.1) | 0.73% | — | IBM Security Access Manager | 6/10/2020 | 17/6/2026 | IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172131. | |
| Modificada | Media (6.5) | 0.93% | — | IBM Security Access Manager | 20/5/2020 | 17/6/2026 | IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing id_token claims manipulation without verification. IBM X-Force ID: 181481. | |
| Modificada | Media (5.4) | 0.71% | — | Oracle Access Manager | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: SSO Engine). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful… | |
| Modificada | Media (4.3) | 1.4% | — | Oracle Access Manager | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Federation). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful… | |
| Modificada | Media (4.6) | 0.76% | — | Oracle Access Manager | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager.… | |
| Modificada | Crítica (9.8) | 4.8% | — | Seling Visual Access Manager | 26/2/2020 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. An attacker without authentication is able to execute arbitrary operating system command by injecting the vulnerable parameter in the PHP Web page /common/vam_monitor_sap.php. | |
| Modificada | Media (5.3) | 1.2% | — | Seling Visual Access Manager | 26/2/2020 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several full path disclosure vulnerability were discovered. A user, even with no authentication, may simply send arbitrary content to the vulnerable pages to generate error messages that expose some full paths. | |
| Modificada | Media (6.5) | 1.1% | — | Seling Visual Access Manager | 26/2/2020 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is able to read XML files on the filesystem via the web interface. The PHP page /common/vam_editXml.php doesn't check the parameter that identifies the file name to be read. Thus, an attacker can… | |
| Modificada | Media (5.4) | 0.86% | — | Seling Visual Access Manager | 26/2/2020 | 17/6/2026 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Reflected Cross-site scripting (XSS) vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via the web pages /vam/vam_anagraphic.php, /vam/vam_vamuser.php, /common/vamp_main.php, and… |