Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.5) | 0.28% | — | Secret ServerAI | 15/9/2026 | 18/9/2026 | Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user. | |
| Pendiente de análisis | Crítica (9.1) | 0.20% | — | Delinea Secret ServerAI | 15/9/2026 | 18/9/2026 | An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed. | |
| Analizada | Media (5.3) | 0.45% | — | Delinea Secret Server | 27/1/2026 | 17/6/2026 | Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue affects Secret Server On-Prem: 11.8.1, 11.9.6, 11.9.25. A secret with "change password on check in" enabled automatically checks in even when the password change fails after reaching its retry limit.… | |
| Analizada | Media (4) | 0.16% | — | Delinea Secret Server | 2/7/2025 | 17/6/2026 | Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables. | |
| Aplazada | Baja (3.8) | 0.15% | — | Thycotic Secret ServerAI | 2/7/2025 | 17/6/2026 | The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow an attacker to impersonate another distributed engine. | |
| Analizada | Alta (8.3) | 0.71% | — | Delinea Secret Server | 26/12/2024 | 17/6/2026 | Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the protocol handler function, URI's were compared before normalization and canonicalization, potentially leading to over matching against the approved list. If this attack were successfully exploited, a… | |
| Analizada | Alta (8.8) | 1.0% | — | Delinea Secret Server | 28/4/2024 | 17/6/2026 | Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is related to a hardcoded key, the use of the integer 2 for the Admin user, and removal of the oauthExpirationId attribute. | |
| Analizada | Media (4.3) | 0.40% | — | Delinea Secret Server | 14/3/2024 | 17/6/2026 | Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is enabled, to view system reports and modify custom reports via the Report functionality in the Web UI. | |
| Analizada | Alta (8.4) | 0.59% | — | Delinea Secret Server | 14/3/2024 | 17/6/2026 | In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained… | |
| Analizada | Media (5.3) | 0.48% | — | Delinea Secret Server | 14/3/2024 | 17/6/2026 | User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a difference in responses from the /oauth2/token endpoint. | |
| Analizada | Media (6.7) | 0.08% | — | Delinea Secret Server | 14/3/2024 | 17/6/2026 | In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and… | |
| Analizada | Media (5.9) | 0.25% | — | Delinea Distributed EngineDelinea Secret Server | 14/3/2024 | 17/6/2026 | Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to encrypt RabbitMQ messages) via crafted payloads to the /pre-authenticate, /authenticate, and /execute-and-respond REST API endpoints. This makes it possible for… | |
| Modificada | Alta (7.2) | 0.32% | — | Delinea Secret Server | 6/9/2023 | 17/6/2026 | Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform software updates without proper integrity verification mechanisms. In this scenario, the update process lacks digital signatures and fails to… | |
| Modificada | Media (4.9) | 0.34% | — | Delinea Secret Server | 6/9/2023 | 17/6/2026 | File accessibility vulnerability in Delinea Secret Server, in its v10.9.000002 and v11.4.000002 versions. Exploitation of this vulnerability could allow an authenticated user with administrative privileges to create a backup file in the application's webroot directory, changing the default backup directory to the… | |
| Modificada | Media (4.3) | 0.52% | — | Jenkins Thycotic Secret Server | 12/4/2023 | 17/6/2026 | A missing permission check in Jenkins Thycotic Secret Server Plugin 1.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.68% | — | Thycotic Secret Server | 1/10/2021 | 17/6/2026 | A SQL injection issue was discovered in ThycoticCentrify Secret Server before 11.0.000007. The only affected versions are 10.9.000032 through 11.0.000006. | |
| Modificada | Media (5.3) | 0.87% | — | IBM Security Secret Server | 14/9/2021 | 17/6/2026 | IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 199328. | |
| Modificada | Media (5.3) | 0.94% | — | IBM Security Secret Server | 14/9/2021 | 17/6/2026 | IBM Security Secret Server up to 11.0 could allow an attacker to enumerate usernames due to improper input validation. IBM X-Force ID: 199243. | |
| Modificada | Media (4.3) | 0.97% | — | IBM Security Secret Server | 14/9/2021 | 17/6/2026 | IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199322. | |
| Modificada | Media (4.3) | 0.50% | — | IBM Security Secret Server | 21/12/2020 | 17/6/2026 | IBM Security Secret Server 10.6 stores potentially sensitive information in config files that could be read by an authenticated user. IBM X-Force ID: 190048. | |
| Modificada | Media (4.9) | 1.1% | — | IBM Security Secret Server | 21/12/2020 | 17/6/2026 | IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190046. | |
| Modificada | Media (5.9) | 1.2% | — | IBM Security Secret Server | 21/12/2020 | 17/6/2026 | IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 190045. | |
| Modificada | Media (6.1) | 0.91% | — | IBM Security Secret Server | 21/12/2020 | 17/6/2026 | IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would… | |
| Modificada | Media (4.3) | 0.69% | — | IBM Security Secret Server | 23/9/2020 | 17/6/2026 | IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate validation. IBM X-Force ID: 178180. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Security Secret Server | 23/9/2020 | 17/6/2026 | IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improper input validation. IBM X-Force ID: 177515. |