Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.90%—CA Privileged Access Manager18/6/201817/6/2026
A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link.
ModificadaAlta (7.5)1.3%—Broadcom Privileged Access Manager18/6/201817/6/2026
A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request.
ModificadaAlta (7.5)1.4%—Broadcom Privileged Access Manager18/6/201817/6/2026
An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input.
ModificadaMedia (5.3)1.1%—Broadcom Privileged Access Manager18/6/201817/6/2026
An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file.
ModificadaAlta (8.8)1.9%—Broadcom Privileged Access Manager18/6/201817/6/2026
An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary commands by passing specially crafted arguments to the update_crld script.
ModificadaCrítica (9.8)13%💥 ExploitBroadcom Privileged Access Manager18/6/201817/6/2026
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.
ModificadaCrítica (9.8)9.6%💥 ExploitBroadcom Privileged Access Manager18/6/201817/6/2026
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.
ModificadaCrítica (9.8)21%💥 ExploitBroadcom Privileged Access ManagerXceedium Xsuite18/6/201817/6/2026
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
ModificadaMedia (4.3)1.8%—IBM Security Access ManagerIBM Security Access Manager FOR WEBIBM Security Access Manager FOR Mobile6/6/201817/6/2026
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
ModificadaMedia (5.9)2.3%—IBM Security Access ManagerIBM Security Access Manager FOR WEBIBM Security Access Manager FOR Mobile6/6/201817/6/2026
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in…
ModificadaMedia (5.3)1.7%—IBM Security Access ManagerIBM Security Access Manager FOR MobileIBM Security Access Manager FOR WEB6/6/201817/6/2026
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 128606.
ModificadaAlta (7.5)0.85%—IBM Security Access Manager FOR WEB FirmwareIBM Security Access Manager FOR MobileIBM Security Access Manager Firmware23/4/201817/6/2026
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 128605.
ModificadaCrítica (9)21%💥 PoCOracle Access Manager19/4/201817/6/2026
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Authentication Engine). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access…
ModificadaAlta (7.6)1.3%—Oracle Adaptive Access Manager19/4/201817/6/2026
Vulnerability in the Oracle Adaptive Access Manager component of Oracle Fusion Middleware (subcomponent: OAAM Admin). The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Adaptive Access Manager.…
ModificadaCrítica (9.3)2.2%—Oracle Access Manager19/4/201817/6/2026
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin). Supported versions that are affected are 10.1.4.3.0, 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access…
ModificadaMedia (6.5)2.0%—Oracle Access ManagerOracle Adaptive Access Manager19/4/201817/6/2026
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin). Supported versions that are affected are 10.1.4.3.0, 11.1.2.3.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access…
ModificadaMedia (4.8)0.61%—Netiq Access Manager14/3/201817/6/2026
A cross site scripting vulnerability exist in the Administration Console in NetIQ Access Manager (NAM) 4.3 and 4.4.
ModificadaAlta (8.8)0.52%—Netiq Access Manager14/3/201817/6/2026
A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.
ModificadaMedia (5.9)0.40%—IBM Security Access ManagerIBM Tivoli Federated Identity Manager8/3/201817/6/2026
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without…
ModificadaMedia (6.1)0.78%—Netiq Access Manager2/3/201817/6/2026
Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result page using the "a" parameter.
ModificadaMedia (6.1)0.75%—Netiq Access Manager2/3/201817/6/2026
A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description" field that could be specified by the provider.
ModificadaMedia (6.1)1.0%—Netiq Access Manager2/3/201817/6/2026
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.
ModificadaMedia (6.1)0.74%—Netiq Access Manager2/3/201817/6/2026
Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using the url parameter.
ModificadaMedia (6.1)0.74%—Netiq Access Manager1/3/201817/6/2026
A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter of the policy editor could allowed code injection into pages of authenticated users.
ModificadaMedia (6.1)0.74%—Netiq Access Manager1/3/201817/6/2026
A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be used to inject javascript code into the login page.
Orbitaley — Vulnerabilidades