Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.21% | — | RSA Securid Authentication ManagerAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial parameter is not masked and is shown in… | |
| Modificada | Alta (7.5) | 0.41% | — | Pingidentity RSA Securid Integration KIT | 18/8/2021 | 17/6/2026 | In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur. | |
| Modificada | Media (6.7) | 0.56% | — | RSA Securid WEB Agent | 23/12/2015 | 17/6/2026 | EMC RSA SecurID Web Agent before 8.0 allows physically proximate attackers to bypass the privacy-screen protection mechanism by leveraging an unattended workstation and running DOM Inspector. | |
| Modificada | Baja (2.1) | 1.3% | — | RSA Authentication APIRSA Securid WEB AgentRSA Pluggable Authentication Module AgentRSA Authentication Agent | 22/5/2013 | 16/6/2026 | EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the… | |
| Modificada | Media (5) | 1.1% | — | EMC RSA Authentication ManagerRSA Authentication ManagerRSA Securid Appliance | 13/7/2012 | 16/6/2026 | EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 do not properly use frames, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "Cross frame scripting vulnerability." | |
| Modificada | Media (6.4) | 1.3% | — | EMC RSA Authentication ManagerRSA Authentication ManagerRSA Securid Appliance | 13/7/2012 | 16/6/2026 | Open redirect vulnerability in the Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 0.98% | — | EMC RSA Authentication ManagerRSA Authentication ManagerRSA Securid Appliance | 13/7/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the (1) Self-Service Console and (2) Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.6) | 2.7% | — | RSA Securid Software Token Converter | 6/3/2012 | 16/6/2026 | Buffer overflow in EMC RSA SecurID Software Token Converter before 2.6.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 1.7% | — | RSA Securid | 17/12/2011 | 16/6/2026 | Untrusted search path vulnerability in EMC RSA SecurID Software Token 4.1 before 4.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Software Token file. | |
| Modificada | Alta (7.5) | 2.6% | — | RSA Securid WEB Agent | 6/5/2005 | 16/6/2026 | Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data. | |
| Modificada | Baja (2.1) | 2.2% | — | Microsoft Exchange ServerRSA Securid | 12/8/2002 | 16/6/2026 | An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA. | |
| Modificada | Alta (7.5) | 1.6% | — | RSA Securid | 24/10/2001 | 16/6/2026 | WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.8% | — | RSA Securid | 22/10/2001 | 16/6/2026 | Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to access restricted resources via URL-encoded (1) /.. or (2) \.. sequences. |