Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.17% | — | Imprivata Enterprise Access ManagementAI | 23/7/2025 | 17/6/2026 | A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen of the shared kiosk workstation and allows unauthorized access to the underlying Windows system through the already logged-in autologon account due to insufficient handling of keyboard shortcuts.… | |
| Aplazada | Media (5.3) | 0.33% | — | Amazon IAM Identity CenterAIAmazon Temporary Elevated Access ManagementAI | 4/3/2025 | 17/6/2026 | Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof an approval in TEAM. Upgrade TEAM to the latest release v.1.2.2. Follow instructions in updating TEAM documentation for updating process | |
| Analizada | Media (5.1) | 0.23% | — | Forgerock Access Management | 29/10/2024 | 17/6/2026 | An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks | |
| Modificada | Media (6.8) | 0.30% | — | Broadcom Symantec Privileged Access Management | 15/7/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI. | |
| Modificada | Alta (7.5) | 0.51% | — | Access Management Specialist Project Access Management Specialist | 24/6/2024 | 17/6/2026 | An issue in Shenzhen Weitillage Industrial Co., Ltd the access management specialist V6.62.51215 allows a remote attacker to obtain sensitive information. | |
| Modificada | Crítica (9.8) | 0.78% | — | Forgerock Access Management | 27/3/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2. | |
| Modificada | Alta (8.8) | 1.5% | — | Nokia Access Management System | 5/9/2023 | 17/6/2026 | An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the service. | |
| Modificada | Media (5.4) | 0.56% | — | Okta Imprivata Privileged Access Management | 20/7/2023 | 17/6/2026 | Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS. | |
| Modificada | Crítica (9.8) | 0.91% | — | Forgerock Access Management | 14/4/2023 | 17/6/2026 | Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0. | |
| Modificada | Media (6.5) | 0.60% | — | Forgerock Access Management | 27/10/2022 | 17/6/2026 | An attacker can use the unrestricted LDAP queries to determine configuration entries | |
| Modificada | Media (6.5) | 0.40% | — | Forgerock Access Management | 27/10/2022 | 17/6/2026 | It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services. | |
| Modificada | Alta (8.8) | 0.84% | — | Broadcom Symantec Privileged Access Management | 26/8/2022 | 17/6/2026 | A malicious unauthorized PAM user can access the administration configuration data and change the values. | |
| Modificada | Crítica (9.8) | 2.0% | — | Forgerock Access Management | 14/2/2022 | 17/6/2026 | Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all… | |
| Modificada | Alta (7.8) | 0.24% | — | Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System | 19/1/2022 | 17/6/2026 | The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protection and make unauthorized changes to… | |
| Modificada | Alta (7.1) | 0.14% | — | Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System | 19/1/2022 | 17/6/2026 | Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this vulnerability to decrypt and modify network… | |
| Modificada | Crítica (9.8) | 1.4% | — | Forgerock Access Management | 25/8/2021 | 17/6/2026 | In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion. | |
| Modificada | Crítica (9.8) | 1.2% | — | Forgerock Access Management | 25/8/2021 | 17/6/2026 | ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Forgerock Access ManagementForgerock Openam | 22/7/2021 | 17/6/2026 | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the… | |
| Modificada | Media (4.7) | 0.84% | — | Oracle Cloud Infrastructure Identity AND Access Management | 22/12/2020 | 17/6/2026 | Vulnerability in the Oracle Cloud Infrastructure Identity and Access Management product of Oracle Cloud Services. Easily exploitable vulnerability allows high privileged attacker with network access to compromise Oracle Cloud Infrastructure Identity and Access Management. Successful attacks of this vulnerability can… | |
| Modificada | Media (6.1) | 0.79% | — | Forgerock Access ManagementForgerock Openam | 19/6/2019 | 17/6/2026 | Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS. | |
| Modificada | Media (6.1) | 0.79% | — | Forgerock Access ManagementForgerock Openam | 19/6/2019 | 17/6/2026 | OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect. | |
| Modificada | Media (6.5) | 0.86% | — | Forgerock Access Management | 21/2/2018 | 17/6/2026 | The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding an ID value in a log file. | |
| Modificada | Media (5.9) | 0.88% | — | Samsung Knox Enterprise Mobility ManagementSamsung Knox Identity Access Management | 20/2/2018 | 17/6/2026 | In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain… | |
| Modificada | Media (6.5) | 2.2% | — | Microfocus Host Access Management AND Security ServerMicrofocus Reflection FOR THE WEBMicrofocus Reflection Security GatewayMicrofocus Reflection ZFE | 29/11/2016 | 17/6/2026 | Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal.… | |
| Modificada | Crítica (9.8) | 19% | — | HP Intelligent Management Center Application Performance ManagerHP Intelligent Management Center Branch Intelligent Management SystemHP Intelligent Management Center Endpoint Admission DefenseHP Intelligent Management Center Network Traffic Analyzer+2 | 15/7/2016 | 17/6/2026 | HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections… |