Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
–

242 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.18%—WP Verify APIAI28/9/202628/9/2026
The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate…
Pendiente de análisisAlta (7.5)0.39%—IBM Verify Identity AccessAI15/9/202616/9/2026
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Pendiente de análisisAlta (7.2)0.32%—IBM Verify Identity AccessAI15/9/202616/9/2026
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
Pendiente de análisisAlta (7.5)0.16%—IBM Security Verify Identity Access Reverse ProxyAI15/9/202616/9/2026
IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Pendiente de análisisCrítica (9.8)0.29%—IBM Verify Identity AccessAI15/9/202617/9/2026
IBM Verify Identity Access is vulnerable to a buffer overflow attack.
Pendiente de análisisAlta (7.5)0.31%—IBM Verify Identity AccessAI15/9/202616/9/2026
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Pendiente de análisisCrítica (9.1)0.23%—IBM Verify Identity AccessAI15/9/202617/9/2026
IBM Verify Identity Access containers may not apply management password change operations correctly.
Pendiente de análisisAlta (8.1)0.27%—IBM Verify Identity AccessAI15/9/202619/9/2026
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.
Pendiente de análisisMedia (6.5)0.17%—IBM Security Verify Identity AccessAI15/9/202619/9/2026
IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.
Pendiente de análisisMedia (4.7)0.28%—IBM Verify Identity AccessAI14/9/202616/9/2026
IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear…
Pendiente de análisisMedia (6.1)0.24%—IBM Verify Identity AccessAIIBM Security Verify AccessAIIBM Verify Identity Access ContainerAIIBM Security Verify Access ContainerAI14/9/202616/9/2026
IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001.
Pendiente de análisisAlta (7.5)0.43%—IBM Verify Identity AccessAI14/9/202616/9/2026
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Pendiente de análisisMedia (5.4)0.15%—IBM Verify Identity AccessAI14/9/202619/9/2026
IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.
Pendiente de análisisMedia (6)0.13%—Okta Verify FOR WindowsAI8/9/202610/9/2026
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.
Pendiente de análisisAlta (7.5)0.25%—IBM Verify Identity Access Advanced Access ControlAI4/9/20268/9/2026
IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.
AnalizadaCrítica (9.8)0.40%—IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
AnalizadaAlta (7.5)0.46%—IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202618/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnerable to a denial of service attack.
AnalizadaAlta (8.1)0.35%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request.
AnalizadaAlta (7.2)0.54%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
AnalizadaAlta (8.1)0.45%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy.
AnalizadaAlta (7.2)0.54%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a…
AnalizadaAlta (8.7)0.49%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface that allows attackers to cause denial of service and information disclosure by…
AnalizadaBaja (3.1)0.29%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 Reverse Proxy in certain configurations is vulnerable to a denial of service attack.
AnalizadaAlta (7.4)0.32%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
AnalizadaMedia (5.3)0.40%—IBM Verify Identity AccessIBM Verify Identity Access Container30/7/202612/8/2026
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error…