Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.21% | — | RSA Securid Authentication ManagerAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial parameter is not masked and is shown in… | |
| Aplazada | Media (4.3) | 0.46% | — | RSA Authentication ManagerAI | 17/2/2025 | 17/6/2026 | RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur. | |
| Modificada | Media (4.8) | 0.64% | — | EMC RSA Authentication Manager | 15/4/2020 | 17/6/2026 | RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the… | |
| Modificada | Media (4.8) | 0.67% | — | EMC RSA Authentication Manager | 26/3/2020 | 17/6/2026 | RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the… | |
| Modificada | Media (4.8) | 0.67% | — | EMC RSA Authentication Manager | 26/3/2020 | 17/6/2026 | RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the… | |
| Modificada | Media (6.5) | 1.1% | — | EMC RSA Authentication Manager | 3/1/2020 | 17/6/2026 | RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by supplying specially crafted XML message. | |
| Modificada | Media (4.8) | 0.56% | — | EMC RSA Authentication ManagerRSA Authentication Manager | 3/12/2019 | 17/6/2026 | RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a… | |
| Modificada | Alta (7.2) | 2.0% | — | EMC RSA Authentication ManagerRSA Authentication Manager | 13/3/2019 | 17/6/2026 | RSA Authentication Manager versions prior to 8.4 P1 contain an Insecure Credential Management Vulnerability. A malicious Operations Console administrator may be able to obtain the value of a domain password that another Operations Console administrator had set previously and use it for attacks. | |
| Modificada | Alta (7.8) | 0.42% | — | RSA Authentication Manager | 16/1/2019 | 17/6/2026 | The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with a crafted license that if used during the quick setup deployment of the initial RSA Authentication Manager system,… | |
| Modificada | Media (4.7) | 1.5% | — | RSA Authentication ManagerEMC RSA Authentication Manager | 28/9/2018 | 17/6/2026 | RSA Authentication Manager versions prior to 8.3 P3 contain a reflected cross-site scripting vulnerability in a Security Console page. A remote, unauthenticated malicious user, with the knowledge of a target user's anti-CSRF token, could potentially exploit this vulnerability by tricking a victim Security Console user… | |
| Modificada | Media (6.1) | 2.0% | — | RSA Authentication ManagerEMC RSA Authentication Manager | 28/9/2018 | 17/6/2026 | RSA Authentication Manager versions prior to 8.3 P3 are affected by a DOM-based cross-site scripting vulnerability which exists in its embedded MadCap Flare Help files. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or… | |
| Modificada | Media (4.8) | 1.1% | — | EMC RSA Authentication ManagerRSA Authentication Manager | 28/9/2018 | 17/6/2026 | RSA Authentication Manager versions prior to 8.3 P3 contain a stored cross-site scripting vulnerability in the Operations Console. A malicious Operations Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console… | |
| Modificada | Media (6.1) | 2.0% | — | EMC RSA Authentication Manager | 21/6/2018 | 17/6/2026 | RSA Authentication Manager Security Console, versions 8.3 P1 and earlier, contains a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim Security Console administrator to supply malicious HTML or JavaScript code to a… | |
| Modificada | Media (6.1) | 1.5% | — | EMC RSA Authentication Manager | 21/6/2018 | 17/6/2026 | RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console… | |
| Modificada | Media (6.1) | 1.4% | — | RSA Authentication Manager | 8/5/2018 | 17/6/2026 | RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially poison HTTP cache and subsequently redirect users to arbitrary web domains. | |
| Modificada | Alta (7.1) | 16% | — | RSA Authentication Manager | 8/5/2018 | 17/6/2026 | RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application. | |
| Modificada | Media (4.3) | 1.2% | — | EMC RSA Authentication Manager | 25/1/2018 | 17/6/2026 | The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulnerability. Authenticated malicious users could potentially exploit this vulnerability to read any unencrypted data from the database. | |
| Modificada | Media (5.4) | 0.89% | — | EMC RSA Authentication Manager | 28/11/2017 | 17/6/2026 | EMC RSA Authentication Manager before 8.2 SP1 P6 has a cross-site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Media (6.1) | 1.2% | — | EMC RSA Authentication Manager | 31/10/2017 | 17/6/2026 | EMC RSA Authentication Manager 8.2 SP1 P4 and earlier contains a reflected cross-site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Media (5.9) | 2.1% | — | EMC RSA Authentication Manager | 17/7/2017 | 17/6/2026 | In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute force attack to attempt to identify that user's PIN. The malicious user could potentially reset the compromised PIN to affect victim's… | |
| Modificada | Media (4.8) | 0.90% | — | EMC RSA Authentication Manager | 17/7/2017 | 17/6/2026 | In EMC RSA Authentication Manager 8.2 SP1 and earlier, a malicious RSA Security Console Administrator could craft a token profile and store the profile name in the RSA Authentication Manager database. The profile name could include a crafted script (with an XSS payload) that could be executed when viewing or editing… | |
| Modificada | Alta (8.1) | 2.2% | — | EMC Authentication Manager Prime | 22/8/2016 | 17/6/2026 | The Self-Service Portal in EMC RSA Authentication Manager (AM) Prime Self-Service 3.0 and 3.1 before 3.1 1915.42871 allows remote authenticated users to cause a denial of service (PIN change for an arbitrary user) via a modified token serial number within a PIN change request, related to a "direct object reference… | |
| Modificada | Media (5.3) | 2.1% | — | EMC RSA Authentication Manager | 7/5/2016 | 17/6/2026 | CRLF injection vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | |
| Modificada | Media (6.1) | 1.6% | — | EMC RSA Authentication Manager | 7/5/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0900. | |
| Modificada | Media (6.1) | 1.6% | — | EMC RSA Authentication Manager | 7/5/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-0901. |