Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.86%—Seling Visual Access Manager26/2/202017/6/2026
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Stored Cross-site scripting (XSS) vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via the web pages /monitor/s_headmodel.php and /vam/vam_user.php.
ModificadaAlta (7.5)1.3%—Seling Visual Access Manager26/2/202017/6/2026
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of files, are reachable by any user without checking for user identity and authorization.
ModificadaAlta (8.8)1.5%—Seling Visual Access Manager26/2/202017/6/2026
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is able to create and write XML files on the filesystem via /common/vam_editXml.php in the web interface. The vulnerable PHP page checks none of these: the parameter that identifies the file name to be…
ModificadaMedia (6.5)0.55%—Seling Visual Access Manager26/2/202017/6/2026
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery (CSRF) on any HTML form. An attacker can exploit the vulnerability to abuse functionalities such as change password, add user, add privilege, and so on.
ModificadaAlta (7.5)1.3%—Seling Visual Access Manager26/2/202017/6/2026
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. An attacker without authentication is able to execute arbitrary SQL SELECT statements by injecting the HTTP (POST or GET) parameter persoid into /tools/VamPersonPhoto.php. The SQL Injection type is Error-based (this means that relies…
ModificadaAlta (7.1)1.4%—IBM Security Access Manager28/1/202017/6/2026
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitOracle Access ManagerOracle CoherenceOracle Commerce PlatformOracle Communications Diameter Signaling Router+515/1/202017/6/2026
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle…
ModificadaAlta (7.2)3.3%—Vasyltech Advanced Access Manager13/1/202017/6/2026
WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaMedia (6.5)0.73%💥 PoCOneidentity Cloud Access Manager4/11/201917/6/2026
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.
ModificadaAlta (8.1)0.85%💥 PoCOneidentity Cloud Access Manager4/11/201917/6/2026
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.
ModificadaAlta (7.5)1.4%—IBM Security Access Manager25/10/201917/6/2026
IBM Security Access Manager Appliance could allow unauthenticated attacker to cause a denial of service in the reverse proxy component. IBM X-Force ID: 156159.
ModificadaAlta (8.2)2.8%—IBM Security Access Manager FOR Enterprise Single Sign-on26/8/201917/6/2026
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 164555.
ModificadaAlta (8.8)0.68%—User Access Manager Project User Access Manager20/8/201916/6/2026
The user-access-manager plugin before 1.2 for WordPress has CSRF.
ModificadaAlta (7.4)1.2%💥 PoCOneidentity Cloud Access Manager29/7/201917/6/2026
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.
ModificadaMedia (5.4)0.68%—IBM Security Access Manager25/6/201917/6/2026
IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or functionality to unintended actors. IBM X-Force ID: 158574.
ModificadaMedia (6.1)0.89%—IBM Security Access Manager25/6/201917/6/2026
IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158573.
ModificadaMedia (5.9)0.87%—IBM Security Access Manager25/6/201917/6/2026
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158572.
ModificadaMedia (6.8)1.0%—IBM Security Access Manager25/6/201917/6/2026
IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web…
ModificadaMedia (4.4)0.31%—IBM Security Access Manager25/6/201917/6/2026
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 158515.
ModificadaMedia (5.9)0.87%—IBM Security Access Manager25/6/201917/6/2026
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158512.
ModificadaBaja (3.7)0.58%—IBM Security Access Manager25/6/201917/6/2026
IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-Force ID: 158510.
ModificadaAlta (7.1)0.35%—IBM Security Access Manager25/6/201917/6/2026
IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user which could be used in further attacks against the system. IBM X-Force ID: 158400.
ModificadaAlta (8.8)1.5%—IBM Security Access Manager25/6/201917/6/2026
IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated users to impersonate other users. IBM X-Force ID: 158331.
ModificadaCrítica (9.4)9.6%💥 ExploitLogonbox Nervepoint Access Manager21/3/201917/6/2026
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs), which could allow for the…
Orbitaley — Vulnerabilidades