Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.44% | — | RSA Authentication Agent FOR WEB | 30/3/2018 | 17/6/2026 | RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows Named Pipe were not sufficient to prevent access by unauthorized users. The attacker with local access to the system can exploit this vulnerability to read configuration… | |
| Modificada | Media (6.1) | 1.0% | — | RSA Authentication Agent FOR WEB | 30/3/2018 | 17/6/2026 | RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-site scripting vulnerability. The attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected… | |
| Modificada | Alta (7.5) | 2.7% | — | RSA Authentication Agent FOR WEB | 30/3/2018 | 17/6/2026 | RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow which may occur when handling certain malicious web cookies that have invalid formats. The attacker could exploit this vulnerability to crash the authentication agent and cause a… | |
| Modificada | Crítica (9.8) | 3.0% | — | RSA Authentication Agent FOR WEB | 29/11/2017 | 17/6/2026 | EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Build 618 have a security vulnerability that could potentially lead to authentication bypass. | |
| Modificada | Media (5) | 1.6% | — | RSA Authentication Agent FOR WEB | 24/9/2010 | 16/6/2026 | Directory traversal vulnerability in RSA Authentication Agent 7.0 before P2 for Web allows remote attackers to read unspecified data via unknown vectors. | |
| Modificada | Media (6.4) | 55% | — | RSA Authentication Agent FOR WEB | 31/12/2005 | 16/6/2026 | Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attackers to execute arbitrary code via a long url parameter in the Redirect method. | |
| Modificada | Media (4.3) | 2.2% | — | RSA Authentication Agent FOR WEB | 27/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter in a GetPic operation. | |
| Modificada | Media (4.3) | 2.5% | — | RSA Authentication Agent FOR WEB | 14/4/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the RSA Authentication Agent for Web 5.2 allows remote attackers to inject arbitrary web script or HTML via the postdata parameter. |