Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 1.3% | — | Redhat KeycloakRedhat Single Sign-on | 23/7/2018 | 17/6/2026 | keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server. | |
| Modificada | Media (6.1) | 0.88% | — | Vmware Single Sign-on FOR Pivotal Cloud Foundry | 27/11/2017 | 17/6/2026 | In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks. | |
| Modificada | Media (6.1) | 0.88% | — | Vmware Single Sign-on FOR Pivotal Cloud Foundry | 9/9/2017 | 17/6/2026 | In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputting code in the text field for an organization name. | |
| Modificada | Media (6.5) | 1.1% | — | Vmware Single Sign-on FOR Pivotal Cloud Foundry | 9/9/2017 | 17/6/2026 | In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service dashboard. Privileged users can in some cases upload malformed XML leading to exposure of data on the Single Sign-On… | |
| Modificada | Crítica (9.1) | 1.5% | — | Broadcom Single Sign-on | 24/3/2016 | 17/6/2026 | The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR5 allow remote attackers to cause a denial of service (daemon crash) or obtain sensitive information via a crafted request. | |
| Modificada | Crítica (9.1) | 1.5% | — | Broadcom Single Sign-on | 24/3/2016 | 17/6/2026 | The Domino web agent in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, R12.5 before CR5, R12.51 before CR4, and R12.52 before SP1 CR3 allows remote attackers to cause a denial of service (daemon crash) or obtain sensitive information via a crafted request. | |
| Modificada | Media (5.8) | 1.5% | — | Services Single Sign-on Server Helper Project Services Single Sign-on Server Helper | 5/3/2015 | 17/6/2026 | Open redirect vulnerability in the Services single sign-on server helper (services_sso_server_helper) module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters. | |
| Modificada | Alta (10) | 95% | 💥 Exploit | GNU GlibcOracle Communications Application Session ControllerOracle Communications Eagle Application ProcessorOracle Communications Eagle LNP Application Processor+14 | 28/1/2015 | 17/6/2026 | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST." | |
| Modificada | Baja (3.5) | 0.85% | — | IBM Security Access Manager FOR Enterprise Single Sign-on | 23/12/2013 | 16/6/2026 | The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request. | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Security Access Manager FOR Enterprise Single Sign-on | 22/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form. | |
| Modificada | Media (4.3) | 0.93% | — | IBM Security Access Manager FOR Enterprise Single Sign-on | 22/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote attackers to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form. | |
| Modificada | Media (5.8) | 2.5% | — | Josso Java Open Single Sign-on Project Home | 9/10/2012 | 16/6/2026 | Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack." |