Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | 0.44% | — | Fortra Core Privileged Access ManagerAI | 1/10/2026 | 1/10/2026 | Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing. | |
| Analizada | Alta (8.8) | 1.0% | — | Fortra Core Privileged Access Manager Server | 15/6/2026 | 28/7/2026 | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client… | |
| Analizada | Crítica (9.8) | 1.5% | — | Fortra Core Privileged Access Manager Server | 15/6/2026 | 28/7/2026 | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing. | |
| Analizada | Alta (8.7) | 0.63% | — | Paloaltonetworks Idira Privileged Access Manager Vault | 12/6/2026 | 7/7/2026 | Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized… | |
| Aplazada | Media (6.2) | 0.10% | — | Fortra Core Privileged Access ManagerAIFortra Boks Server AgentAI | 16/12/2025 | 17/6/2026 | Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain. | |
| Aplazada | Media (5.5) | 0.14% | — | Fortra Core Privileged Access ManagerAI | 17/6/2025 | 17/6/2026 | A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) and also legacy tar installs of BoKS 7.2 without hotfix #0474 on Linux, AIX, and Solaris allows low privilege local… | |
| Aplazada | Media (4.2) | 0.23% | — | Cyberark Privileged Access ManagerAI | 3/2/2025 | 17/6/2026 | PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping. | |
| Analizada | Media (6.1) | 0.16% | — | Cyberark Privileged Access Manager | 3/2/2025 | 17/6/2026 | PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection. | |
| Aplazada | Alta (8) | 0.38% | — | Opentext Privileged Access ManagerAI | 19/12/2024 | 17/6/2026 | In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5) | |
| Analizada | Alta (7.8) | 0.31% | — | Microfocus Netiq Privileged Access Manager | 21/8/2024 | 17/6/2026 | SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1. | |
| Analizada | Alta (7.5) | 0.33% | — | Microfocus Netiq Privileged Access Manager | 21/8/2024 | 17/6/2026 | A vulnerability found in OpenText Privileged Access Manager that issues a token. on successful issuance of the token, a cookie gets set that allows unrestricted access to all the application resources. This issue affects Privileged Access Manager before 3.7.0.1. | |
| Modificada | Crítica (9.1) | 1.7% | — | Broadcom Privileged Access Manager | 26/2/2019 | 17/6/2026 | An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configuration. | |
| Modificada | Crítica (9.8) | 1.7% | — | Broadcom Privileged Access Manager | 18/6/2018 | 17/6/2026 | An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks. | |
| Modificada | Alta (7.5) | 0.90% | — | Broadcom Privileged Access Manager | 18/6/2018 | 17/6/2026 | Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking. | |
| Modificada | Media (6.1) | 0.90% | — | CA Privileged Access Manager | 18/6/2018 | 17/6/2026 | A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link. | |
| Modificada | Alta (7.5) | 1.3% | — | Broadcom Privileged Access Manager | 18/6/2018 | 17/6/2026 | A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request. | |
| Modificada | Alta (7.5) | 1.4% | — | Broadcom Privileged Access Manager | 18/6/2018 | 17/6/2026 | An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input. | |
| Modificada | Media (5.3) | 1.1% | — | Broadcom Privileged Access Manager | 18/6/2018 | 17/6/2026 | An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file. | |
| Modificada | Alta (8.8) | 1.9% | — | Broadcom Privileged Access Manager | 18/6/2018 | 17/6/2026 | An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary commands by passing specially crafted arguments to the update_crld script. | |
| Modificada | Crítica (9.8) | 13% | — | Broadcom Privileged Access Manager | 18/6/2018 | 17/6/2026 | An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file. | |
| Modificada | Crítica (9.8) | 9.6% | — | Broadcom Privileged Access Manager | 18/6/2018 | 17/6/2026 | An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests. | |
| Modificada | Crítica (9.8) | 21% | — | Broadcom Privileged Access ManagerXceedium Xsuite | 18/6/2018 | 17/6/2026 | An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands. |