Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | 0.44% | — | Fortra Core Privileged Access ManagerAI | 1/10/2026 | 1/10/2026 | Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing. | |
| Pendiente de análisis | Media (5) | 0.20% | — | Okta Privileged Access ClientAIOkta ScaleftAI | 8/9/2026 | 10/9/2026 | The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended… | |
| Pendiente de análisis | Media (5.3) | 0.14% | — | Okta Privileged AccessAIOpenbsd OpensshAI | 25/8/2026 | 28/8/2026 | The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process. | |
| Analizada | Alta (8.8) | 1.0% | — | Fortra Core Privileged Access Manager Server | 15/6/2026 | 28/7/2026 | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client… | |
| Analizada | Crítica (9.8) | 1.5% | — | Fortra Core Privileged Access Manager Server | 15/6/2026 | 28/7/2026 | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing. | |
| Analizada | Alta (8.7) | 0.63% | — | Paloaltonetworks Idira Privileged Access Manager Vault | 12/6/2026 | 7/7/2026 | Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized… | |
| Aplazada | Media (5.3) | 0.27% | — | Delinea Cloud SuiteAIDelinea Privileged Access ServiceAI | 18/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service. Remediation: This issue is fixed in Cloud Suite: 25.1 | |
| Aplazada | Media (6.9) | 0.34% | — | Delinea Cloud SuiteAIDelinea Privileged Access ServiceAIDelinea Server SuiteAI | 18/2/2026 | 17/6/2026 | Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privileged Access Service. If you're not using the latest Server Suite agents, this fix requires that you upgrade to Server Suite 2023.1 (agent 6.0.1) or later. * If you cannot upgrade to Release 2023.1… | |
| Aplazada | Media (6.2) | 0.10% | — | Fortra Core Privileged Access ManagerAIFortra Boks Server AgentAI | 16/12/2025 | 17/6/2026 | Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain. | |
| Aplazada | Media (5.5) | 0.14% | — | Fortra Core Privileged Access ManagerAI | 17/6/2025 | 17/6/2026 | A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) and also legacy tar installs of BoKS 7.2 without hotfix #0474 on Linux, AIX, and Solaris allows low privilege local… | |
| Aplazada | Media (4.2) | 0.23% | — | Cyberark Privileged Access ManagerAI | 3/2/2025 | 17/6/2026 | PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping. | |
| Analizada | Media (6.1) | 0.16% | — | Cyberark Privileged Access Manager | 3/2/2025 | 17/6/2026 | PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection. | |
| Aplazada | Alta (8) | 0.38% | — | Opentext Privileged Access ManagerAI | 19/12/2024 | 17/6/2026 | In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5) | |
| Aplazada | Alta (7.1) | 0.24% | — | Okta Privileged Access Server AgentAI | 21/11/2024 | 17/6/2026 | Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. To remediate this vulnerability, upgrade the Okta Privileged Access server agent (SFTD) to version 1.87.1 or greater. | |
| Analizada | Alta (7.8) | 0.31% | — | Microfocus Netiq Privileged Access Manager | 21/8/2024 | 17/6/2026 | SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1. | |
| Analizada | Alta (7.5) | 0.33% | — | Microfocus Netiq Privileged Access Manager | 21/8/2024 | 17/6/2026 | A vulnerability found in OpenText Privileged Access Manager that issues a token. on successful issuance of the token, a cookie gets set that allows unrestricted access to all the application resources. This issue affects Privileged Access Manager before 3.7.0.1. | |
| Modificada | Media (6.8) | 0.30% | — | Broadcom Symantec Privileged Access Management | 15/7/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI. | |
| Modificada | Media (4.3) | 0.38% | — | Delinea Privileged Access Service | 2/7/2024 | 17/6/2026 | Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing listing of arbitrary directory outside the root directory of the web application. Versions 23.1-HF7 and on have the patch. | |
| Modificada | Media (6.5) | 0.48% | — | Delinea Privileged Access Service | 2/7/2024 | 17/6/2026 | Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing arbitrary files reading outside the web publish directory. Versions 23.1-HF7 and on have the patch. | |
| Modificada | Media (5.4) | 0.56% | — | Okta Imprivata Privileged Access Management | 20/7/2023 | 17/6/2026 | Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS. | |
| Modificada | Alta (8.8) | 0.84% | — | Broadcom Symantec Privileged Access Management | 26/8/2022 | 17/6/2026 | A malicious unauthorized PAM user can access the administration configuration data and change the values. | |
| Modificada | Crítica (9.1) | 1.7% | — | Broadcom Privileged Access Manager | 26/2/2019 | 17/6/2026 | An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configuration. | |
| Modificada | Crítica (9.8) | 1.7% | — | Broadcom Privileged Access Manager | 18/6/2018 | 17/6/2026 | An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks. | |
| Modificada | Alta (7.5) | 0.90% | — | Broadcom Privileged Access Manager | 18/6/2018 | 17/6/2026 | Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking. | |
| Modificada | Media (6.1) | 0.90% | — | CA Privileged Access Manager | 18/6/2018 | 17/6/2026 | A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link. |