Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7)0.17%—Imprivata Enterprise Access ManagementAI23/7/202517/6/2026
A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen of the shared kiosk workstation and allows unauthorized access to the underlying Windows system through the already logged-in autologon account due to insufficient handling of keyboard shortcuts.…
AplazadaMedia (5.3)0.33%—Amazon IAM Identity CenterAIAmazon Temporary Elevated Access ManagementAI4/3/202517/6/2026
Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof an approval in TEAM. Upgrade TEAM to the latest release v.1.2.2. Follow instructions in updating TEAM documentation for updating process
AnalizadaMedia (5.1)0.23%—Forgerock Access Management29/10/202417/6/2026
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks
ModificadaMedia (6.8)0.30%—Broadcom Symantec Privileged Access Management15/7/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.
ModificadaAlta (7.5)0.51%—Access Management Specialist Project Access Management Specialist24/6/202417/6/2026
An issue in Shenzhen Weitillage Industrial Co., Ltd the access management specialist V6.62.51215 allows a remote attacker to obtain sensitive information.
ModificadaCrítica (9.8)0.78%—Forgerock Access Management27/3/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2.
ModificadaAlta (8.8)1.5%—Nokia Access Management System5/9/202317/6/2026
An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the service.
ModificadaMedia (5.4)0.56%—Okta Imprivata Privileged Access Management20/7/202317/6/2026
Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS.
ModificadaCrítica (9.8)0.91%—Forgerock Access Management14/4/202317/6/2026
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.
ModificadaMedia (6.5)0.60%—Forgerock Access Management27/10/202217/6/2026
An attacker can use the unrestricted LDAP queries to determine configuration entries
ModificadaMedia (6.5)0.40%—Forgerock Access Management27/10/202217/6/2026
It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services.
ModificadaAlta (8.8)0.84%—Broadcom Symantec Privileged Access Management26/8/202217/6/2026
A malicious unauthorized PAM user can access the administration configuration data and change the values.
ModificadaCrítica (9.8)2.0%—Forgerock Access Management14/2/202217/6/2026
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1; 6.5 versions prior to 6.5.4; all…
ModificadaAlta (7.8)0.24%—Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System19/1/202217/6/2026
The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protection and make unauthorized changes to…
ModificadaAlta (7.1)0.14%—Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System19/1/202217/6/2026
Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this vulnerability to decrypt and modify network…
ModificadaCrítica (9.8)1.4%—Forgerock Access Management25/8/202117/6/2026
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.
ModificadaCrítica (9.8)1.2%—Forgerock Access Management25/8/202117/6/2026
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.
AnalizadaCrítica (9.8)100%⚠ Explotación activaForgerock Access ManagementForgerock Openam22/7/202117/6/2026
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the…
ModificadaMedia (4.7)0.84%—Oracle Cloud Infrastructure Identity AND Access Management22/12/202017/6/2026
Vulnerability in the Oracle Cloud Infrastructure Identity and Access Management product of Oracle Cloud Services. Easily exploitable vulnerability allows high privileged attacker with network access to compromise Oracle Cloud Infrastructure Identity and Access Management. Successful attacks of this vulnerability can…
ModificadaMedia (6.1)0.79%—Forgerock Access ManagementForgerock Openam19/6/201917/6/2026
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS.
ModificadaMedia (6.1)0.79%—Forgerock Access ManagementForgerock Openam19/6/201917/6/2026
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect.
ModificadaMedia (6.5)0.86%—Forgerock Access Management21/2/201817/6/2026
The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding an ID value in a log file.
ModificadaMedia (5.9)0.88%—Samsung Knox Enterprise Mobility ManagementSamsung Knox Identity Access Management20/2/201817/6/2026
In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain…
ModificadaMedia (6.5)2.2%—Microfocus Host Access Management AND Security ServerMicrofocus Reflection FOR THE WEBMicrofocus Reflection Security GatewayMicrofocus Reflection ZFE29/11/201617/6/2026
Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal.…
ModificadaCrítica (9.8)19%—HP Intelligent Management Center Application Performance ManagerHP Intelligent Management Center Branch Intelligent Management SystemHP Intelligent Management Center Endpoint Admission DefenseHP Intelligent Management Center Network Traffic Analyzer+215/7/201617/6/2026
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections…