Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

22 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.8)0.44%—Fortra Core Privileged Access ManagerAI1/10/20261/10/2026
Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
AnalizadaAlta (8.8)1.0%—Fortra Core Privileged Access Manager Server15/6/202628/7/2026
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client…
AnalizadaCrítica (9.8)1.5%—Fortra Core Privileged Access Manager Server15/6/202628/7/2026
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
AnalizadaAlta (8.7)0.63%—Paloaltonetworks Idira Privileged Access Manager Vault12/6/20267/7/2026
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized…
AplazadaMedia (6.2)0.10%—Fortra Core Privileged Access ManagerAIFortra Boks Server AgentAI16/12/202517/6/2026
Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.
AplazadaMedia (5.5)0.14%—Fortra Core Privileged Access ManagerAI17/6/202517/6/2026
A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) and also legacy tar installs of BoKS 7.2 without hotfix #0474 on Linux, AIX, and Solaris allows low privilege local…
AplazadaMedia (4.2)0.23%—Cyberark Privileged Access ManagerAI3/2/202517/6/2026
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping.
AnalizadaMedia (6.1)0.16%—Cyberark Privileged Access Manager3/2/202517/6/2026
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.
AplazadaAlta (8)0.38%—Opentext Privileged Access ManagerAI19/12/202417/6/2026
In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)
AnalizadaAlta (7.8)0.31%—Microfocus Netiq Privileged Access Manager21/8/202417/6/2026
SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.
AnalizadaAlta (7.5)0.33%—Microfocus Netiq Privileged Access Manager21/8/202417/6/2026
A vulnerability found in OpenText Privileged Access Manager that issues a token. on successful issuance of the token, a cookie gets set that allows unrestricted access to all the application resources. This issue affects Privileged Access Manager before 3.7.0.1.
ModificadaCrítica (9.1)1.7%—Broadcom Privileged Access Manager26/2/201917/6/2026
An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configuration.
ModificadaCrítica (9.8)1.7%—Broadcom Privileged Access Manager18/6/201817/6/2026
An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks.
ModificadaAlta (7.5)0.90%—Broadcom Privileged Access Manager18/6/201817/6/2026
Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.
ModificadaMedia (6.1)0.90%—CA Privileged Access Manager18/6/201817/6/2026
A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link.
ModificadaAlta (7.5)1.3%—Broadcom Privileged Access Manager18/6/201817/6/2026
A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request.
ModificadaAlta (7.5)1.4%—Broadcom Privileged Access Manager18/6/201817/6/2026
An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input.
ModificadaMedia (5.3)1.1%—Broadcom Privileged Access Manager18/6/201817/6/2026
An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file.
ModificadaAlta (8.8)1.9%—Broadcom Privileged Access Manager18/6/201817/6/2026
An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary commands by passing specially crafted arguments to the update_crld script.
ModificadaCrítica (9.8)13%—Broadcom Privileged Access Manager18/6/201817/6/2026
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.
ModificadaCrítica (9.8)9.6%—Broadcom Privileged Access Manager18/6/201817/6/2026
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.
ModificadaCrítica (9.8)21%—Broadcom Privileged Access ManagerXceedium Xsuite18/6/201817/6/2026
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.