Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.8)0.44%—Fortra Core Privileged Access ManagerAI1/10/20261/10/2026
Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
Pendiente de análisisMedia (5)0.20%—Okta Privileged Access ClientAIOkta ScaleftAI8/9/202610/9/2026
The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended…
Pendiente de análisisMedia (5.3)0.14%—Okta Privileged AccessAIOpenbsd OpensshAI25/8/202628/8/2026
The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.
AnalizadaAlta (8.8)1.0%—Fortra Core Privileged Access Manager Server15/6/202628/7/2026
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client…
AnalizadaCrítica (9.8)1.5%—Fortra Core Privileged Access Manager Server15/6/202628/7/2026
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
AnalizadaAlta (8.7)0.63%—Paloaltonetworks Idira Privileged Access Manager Vault12/6/20267/7/2026
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized…
AplazadaMedia (5.3)0.27%—Delinea Cloud SuiteAIDelinea Privileged Access ServiceAI18/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service. Remediation: This issue is fixed in Cloud Suite: 25.1
AplazadaMedia (6.9)0.34%—Delinea Cloud SuiteAIDelinea Privileged Access ServiceAIDelinea Server SuiteAI18/2/202617/6/2026
Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privileged Access Service. If you're not using the latest Server Suite agents, this fix requires that you upgrade to Server Suite 2023.1 (agent 6.0.1) or later. * If you cannot upgrade to Release 2023.1…
AplazadaMedia (6.2)0.10%—Fortra Core Privileged Access ManagerAIFortra Boks Server AgentAI16/12/202517/6/2026
Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.
AplazadaMedia (5.5)0.14%—Fortra Core Privileged Access ManagerAI17/6/202517/6/2026
A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) and also legacy tar installs of BoKS 7.2 without hotfix #0474 on Linux, AIX, and Solaris allows low privilege local…
AplazadaMedia (4.2)0.23%—Cyberark Privileged Access ManagerAI3/2/202517/6/2026
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping.
AnalizadaMedia (6.1)0.16%—Cyberark Privileged Access Manager3/2/202517/6/2026
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.
AplazadaAlta (8)0.38%—Opentext Privileged Access ManagerAI19/12/202417/6/2026
In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)
AplazadaAlta (7.1)0.24%—Okta Privileged Access Server AgentAI21/11/202417/6/2026
Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. To remediate this vulnerability, upgrade the Okta Privileged Access server agent (SFTD) to version 1.87.1 or greater.
AnalizadaAlta (7.8)0.31%—Microfocus Netiq Privileged Access Manager21/8/202417/6/2026
SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.
AnalizadaAlta (7.5)0.33%—Microfocus Netiq Privileged Access Manager21/8/202417/6/2026
A vulnerability found in OpenText Privileged Access Manager that issues a token. on successful issuance of the token, a cookie gets set that allows unrestricted access to all the application resources. This issue affects Privileged Access Manager before 3.7.0.1.
ModificadaMedia (6.8)0.30%—Broadcom Symantec Privileged Access Management15/7/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.
ModificadaMedia (4.3)0.38%—Delinea Privileged Access Service2/7/202417/6/2026
Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing listing of arbitrary directory outside the root directory of the web application. Versions 23.1-HF7 and on have the patch.
ModificadaMedia (6.5)0.48%—Delinea Privileged Access Service2/7/202417/6/2026
Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing arbitrary files reading outside the web publish directory. Versions 23.1-HF7 and on have the patch.
ModificadaMedia (5.4)0.56%—Okta Imprivata Privileged Access Management20/7/202317/6/2026
Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS.
ModificadaAlta (8.8)0.84%—Broadcom Symantec Privileged Access Management26/8/202217/6/2026
A malicious unauthorized PAM user can access the administration configuration data and change the values.
ModificadaCrítica (9.1)1.7%—Broadcom Privileged Access Manager26/2/201917/6/2026
An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configuration.
ModificadaCrítica (9.8)1.7%—Broadcom Privileged Access Manager18/6/201817/6/2026
An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks.
ModificadaAlta (7.5)0.90%—Broadcom Privileged Access Manager18/6/201817/6/2026
Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.
ModificadaMedia (6.1)0.90%—CA Privileged Access Manager18/6/201817/6/2026
A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link.