Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
302 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 7.3% | 💥 PoC | Fasterxml Jackson-databindOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Autovue FOR Agile Product Lifecycle Management+22 | 17/9/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. | |
| Modificada | Media (6.1) | 0.72% | — | Forgerock Identity Manager | 31/8/2020 | 17/6/2026 | Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.5.0.4, 6.0.0.6. | |
| Modificada | Alta (8.1) | 7.6% | 💥 PoC | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+21 | 25/8/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP). | |
| Modificada | Crítica (9.8) | 1.2% | — | Microfocus Identity Manager | 8/7/2020 | 17/6/2026 | Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prior to 4.7.3 and 4.8.1 hot fix 1. The vulnerability could allow information exposure that can result in an elevation of privilege or an unauthorized access. | |
| Modificada | Baja (2.7) | 0.80% | — | IBM Security Identity Manager Virtual Appliance | 1/7/2020 | 17/6/2026 | IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. IBM X-Force ID: 172016. | |
| Modificada | Baja (2.7) | 0.80% | — | IBM Security Identity Manager Virtual Appliance | 1/7/2020 | 17/6/2026 | IBM Security Identity Manager Virtual Appliance 7.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 172015. | |
| Modificada | Media (4.3) | 0.58% | — | IBM Security Identity Manager Virtual Appliance | 1/7/2020 | 17/6/2026 | IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and… | |
| Modificada | Alta (7.8) | 0.57% | — | IBM Security Identity Manager Virtual Appliance | 1/7/2020 | 17/6/2026 | IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171512. | |
| Modificada | Crítica (9.8) | 1.3% | — | IBM Security Identity Manager | 4/2/2020 | 17/6/2026 | IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511. | |
| Modificada | Media (4.9) | 1.9% | — | IBM Security Identity Manager | 4/2/2020 | 17/6/2026 | IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 171510. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Security Identity Manager | 4/2/2020 | 17/6/2026 | IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163493. | |
| Modificada | Media (5.4) | 0.81% | — | Oracle Identity Manager | 15/1/2020 | 17/6/2026 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of… | |
| Modificada | Alta (7.5) | 2.0% | — | Oracle Identity Manager | 15/1/2020 | 17/6/2026 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM - LDAP user and role Synch). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks… | |
| Modificada | Alta (8.8) | 3.5% | — | IBM Security Identity Manager | 20/11/2019 | 17/6/2026 | IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID:… | |
| Modificada | Media (4.3) | 0.86% | — | Oracle Identity Manager | 23/7/2019 | 17/6/2026 | Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager.… | |
| Modificada | Media (5.3) | 1.3% | — | IBM Security Identity Manager Virtual Appliance | 11/7/2019 | 17/6/2026 | IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 153749. | |
| Modificada | Crítica (9.8) | 89% | 💥 Exploit | Oracle Communications Diameter Signaling RouterOracle Communications Network IntegrityOracle Hyperion Infrastructure TechnologyOracle Identity Manager+5 | 19/6/2019 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic… | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Identity Manager | 9/5/2019 | 17/6/2026 | The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Alta (7.5) | 1.5% | — | IBM Security Privileged Identity Manager | 2/4/2019 | 17/6/2026 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 145236. | |
| Modificada | Alta (8.8) | 3.6% | — | IBM Security Privileged Identity Manager | 2/4/2019 | 17/6/2026 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 144580. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Security Privileged Identity Manager | 2/4/2019 | 17/6/2026 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 144411. | |
| Modificada | Media (4.3) | 0.98% | — | IBM Security Privileged Identity Manager | 2/4/2019 | 17/6/2026 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 144410. | |
| Modificada | Baja (3.3) | 0.36% | — | IBM Security Privileged Identity Manager | 2/4/2019 | 17/6/2026 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 144408. | |
| Modificada | Alta (8.8) | 0.53% | — | IBM Security Privileged Identity Manager | 2/4/2019 | 17/6/2026 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144348. |