Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.6) | 0.24% | — | Broadcom Symantec Siteminder | 10/3/2026 | 17/6/2026 | Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page. | |
| Modificada | Media (5.4) | 3.1% | 💥 Exploit | Broadcom Symantec Siteminder Webagent | 30/5/2023 | 17/6/2026 | A user can supply malicious HTML and JavaScript code that will be executed in the client browser | |
| Modificada | Media (6.1) | 0.72% | — | Broadcom Symantec Siteminder | 28/3/2022 | 16/6/2026 | A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be… |