Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
944 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.51% | — | Pingidentity PingfederateAI | 4/12/2025 | 17/6/2026 | The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication. | |
| Analizada | Crítica (9.8) | 0.24% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+5 | 18/11/2025 | 17/6/2026 | A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to improper validation of client certificate–based authentication in certain default configurations, the affected components may permit… | |
| Analizada | Alta (8.8) | 0.23% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 18/11/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the SameSite=Lax cookie attribute is used as a mitigation, it is ineffective… | |
| Analizada | Media (6.1) | 0.19% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 5/11/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, a malicious actor can inject arbitrary JavaScript into the response, leading to reflected XSS. Successful exploitation could result in… | |
| Analizada | Media (6.1) | 0.21% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity Server | 5/11/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encoding. A malicious actor can inject arbitrary JavaScript payloads into the authentication endpoint, which are reflected back in the response, enabling browser-based attacks.… | |
| Analizada | Alta (7.2) | 0.60% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 5/11/2025 | 17/6/2026 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious actor with administrative privileges can upload a specially crafted file to a user-controlled location within the deployment. Successful… | |
| Analizada | Crítica (9.1) | 0.46% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+4 | 5/11/2025 | 17/6/2026 | An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external entities. A successful attack could enable a remote, unauthenticated attacker… | |
| Analizada | Alta (7.5) | 0.71% | 💥 PoC | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to a logic error when processing a RADIUS access request for a… | |
| Analizada | Media (4.9) | 0.30% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because certain files lack proper data protection mechanisms. An attacker with read-only Administrator privileges could… | |
| Analizada | Media (5.4) | 0.21% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management… | |
| Analizada | Media (5.4) | 3.9% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management… | |
| Analizada | Media (5.4) | 0.21% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management… | |
| Analizada | Alta (7.2) | 0.91% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+4 | 5/11/2025 | 17/6/2026 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with appropriate privileges can upload a malicious file to a user-controlled location on the server, potentially leading to remote code… | |
| Analizada | Media (6.1) | 0.22% | — | Sailpoint Identityiq | 3/11/2025 | 17/6/2026 | IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions allows some IdentityIQ web services that provide non-HTML content to be accessed via a URL path that will set the Content-Type to HTML allowing a requesting browser to… | |
| Aplazada | Ninguna (0) | 0.28% | — | Pingidentity PingfederateAI | 27/10/2025 | 30/9/2026 | Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks. | |
| Analizada | Media (5.3) | 0.85% | 💥 Exploit | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 24/10/2025 | 17/6/2026 | An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure. The known exposure from this… | |
| Analizada | Media (4.8) | 0.62% | 💥 Exploit | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 24/10/2025 | 17/6/2026 | SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepted user-supplied URLs without proper validation, leading to server-side request forgery (SSRF). Additionally, the retrieved content was… | |
| Analizada | Crítica (9.8) | 89% | ⚠ Explotación activa💥 Exploit | Oracle Identity Manager | 21/10/2025 | 17/6/2026 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks… | |
| Analizada | Crítica (9.8) | 0.82% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+5 | 16/10/2025 | 17/6/2026 | Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation. Successful exploitation of this vulnerability could lead to a malicious actor gaining administrative… | |
| Analizada | Media (6.5) | 0.56% | — | Wso2 API Control PlaneWso2 API ManagerWso2 API Manager AnalyticsWso2 Data Analytics Server+11 | 16/10/2025 | 25/9/2026 | An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This… | |
| Analizada | Crítica (9.8) | 0.29% | — | IBM Security Verify AccessIBM Verify Identity Access | 13/10/2025 | 17/6/2026 | IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external… | |
| Analizada | Crítica (9.3) | 0.19% | — | IBM Security Verify AccessIBM Security Verify Access DockerIBM Verify Identity AccessIBM Verify Identity Access Docker | 6/10/2025 | 17/6/2026 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required. | |
| Analizada | Alta (8.5) | 0.17% | — | IBM Security Verify AccessIBM Security Verify Access DockerIBM Verify Identity AccessIBM Verify Identity Access Docker | 6/10/2025 | 17/6/2026 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere. | |
| Analizada | Alta (7.3) | 0.33% | — | IBM Security Verify AccessIBM Security Verify Access DockerIBM Verify Identity AccessIBM Verify Identity Access Docker | 6/10/2025 | 17/6/2026 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input. | |
| Analizada | Alta (7.2) | 0.54% | — | Wso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM | 26/9/2025 | 17/6/2026 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server. By leveraging this… |