Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.0% | — | RSA Authentication ManagerEMC RSA Authentication Manager | 28/9/2018 | 17/6/2026 | RSA Authentication Manager versions prior to 8.3 P3 are affected by a DOM-based cross-site scripting vulnerability which exists in its embedded MadCap Flare Help files. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or… | |
| Modificada | Media (4.8) | 1.1% | — | EMC RSA Authentication ManagerRSA Authentication Manager | 28/9/2018 | 17/6/2026 | RSA Authentication Manager versions prior to 8.3 P3 contain a stored cross-site scripting vulnerability in the Operations Console. A malicious Operations Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console… | |
| Modificada | Media (6.1) | 2.0% | — | EMC RSA Authentication Manager | 21/6/2018 | 17/6/2026 | RSA Authentication Manager Security Console, versions 8.3 P1 and earlier, contains a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim Security Console administrator to supply malicious HTML or JavaScript code to a… | |
| Modificada | Media (6.1) | 1.5% | — | EMC RSA Authentication Manager | 21/6/2018 | 17/6/2026 | RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console… | |
| Modificada | Media (6.1) | 1.4% | — | RSA Authentication Manager | 8/5/2018 | 17/6/2026 | RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially poison HTTP cache and subsequently redirect users to arbitrary web domains. | |
| Modificada | Alta (7.1) | 16% | 💥 Exploit | RSA Authentication Manager | 8/5/2018 | 17/6/2026 | RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application. | |
| Modificada | Media (5.5) | 0.44% | — | RSA Authentication Agent FOR WEB | 30/3/2018 | 17/6/2026 | RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows Named Pipe were not sufficient to prevent access by unauthorized users. The attacker with local access to the system can exploit this vulnerability to read configuration… | |
| Modificada | Media (6.1) | 1.0% | — | RSA Authentication Agent FOR WEB | 30/3/2018 | 17/6/2026 | RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-site scripting vulnerability. The attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected… | |
| Modificada | Alta (7.5) | 2.7% | — | RSA Authentication Agent FOR WEB | 30/3/2018 | 17/6/2026 | RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow which may occur when handling certain malicious web cookies that have invalid formats. The attacker could exploit this vulnerability to crash the authentication agent and cause a… | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service FOR Citrix WEB Interface Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service Windows Logon Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7965. | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service Windows Logon Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7966. | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service FOR NPS Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service for NPS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service FOR AD FS Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service for AD FS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.8) | 0.41% | — | Gemalto Safenet Authentication Service FOR Outlook WEB APP Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service for Outlook Web App Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service Remote WEB Workplace Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service Remote Web Workplace Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service Tokenvalidator Proxy Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service TokenValidator Proxy Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service IIS Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service IIS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.8) | 0.38% | — | Gemalto Safenet Authentication Service END User Software Tools FOR Windows | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service End User Software Tools for Windows uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Media (4.3) | 1.2% | — | EMC RSA Authentication Manager | 25/1/2018 | 17/6/2026 | The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulnerability. Authenticated malicious users could potentially exploit this vulnerability to read any unencrypted data from the database. | |
| Modificada | Media (6.1) | 0.95% | — | Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+4 | 20/12/2017 | 17/6/2026 | The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,… | |
| Modificada | Alta (8.8) | 1.9% | — | Apache Sling Authentication Service | 18/12/2017 | 17/6/2026 | A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials. | |
| Modificada | Crítica (10) | 3.0% | — | EMC RSA Authentication Agent API FOR CEMC RSA Authentication Agent SDK FOR C | 29/11/2017 | 17/6/2026 | EMC RSA Authentication Agent API 8.5 for C and RSA Authentication Agent SDK 8.6 for C allow attackers to bypass authentication, aka an "Error Handling Vulnerability." | |
| Modificada | Crítica (9.8) | 3.0% | — | RSA Authentication Agent FOR WEB | 29/11/2017 | 17/6/2026 | EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Build 618 have a security vulnerability that could potentially lead to authentication bypass. | |
| Modificada | Media (5.4) | 0.89% | — | EMC RSA Authentication Manager | 28/11/2017 | 17/6/2026 | EMC RSA Authentication Manager before 8.2 SP1 P6 has a cross-site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system. |