Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (8.1) | 0.20% | — | Dogtagpki Pki-coreAI | 2/10/2026 | 5/10/2026 | A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream… | |
| Pendiente de análisis | Alta (8.1) | 0.16% | — | Redhat Pki-coreAI | 21/9/2026 | 30/9/2026 | A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's… | |
| Pendiente de análisis | Baja (3.1) | 0.26% | — | Pki-coreAI | 24/7/2026 | 25/7/2026 | A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's… | |
| Aplazada | Alta (7.5) | 0.66% | — | Dogtag-pkiAIPki-coreAI | 11/6/2024 | 26/6/2026 | A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege. | |
| Modificada | Media (5.7) | 0.25% | — | Pki-core Project Pki-coreRedhat Certificate SystemRedhat Enterprise Linux | 14/7/2022 | 17/6/2026 | A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt… | |
| Modificada | Alta (7.5) | 1.3% | — | Pki-core Project Pki-core | 29/8/2017 | 17/6/2026 | Multiple temporary file creation vulnerabilities in pki-core 10.2.0. |