Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
336 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.89% | — | 1password | 9/1/2020 | 17/6/2026 | AgileBits 1Password through 1.0.9.340 allows security feature bypass | |
| Modificada | Media (6.5) | 0.87% | — | Norton Password Manager | 5/12/2019 | 17/6/2026 | Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information. | |
| Modificada | Media (6.3) | 0.34% | — | Norton Password Manager | 5/12/2019 | 17/6/2026 | Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served. | |
| Modificada | Media (6.3) | 0.34% | — | Norton Password Manager | 5/12/2019 | 17/6/2026 | Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served. | |
| Modificada | Alta (7.5) | 2.9% | — | Trendmicro Password Manager | 25/11/2019 | 17/6/2026 | Trend Micro Password Manager versions 3.x, 5.0, and 5.1 for Android is affected by a FLAG_MISUSE vulnerability that could be exploited to allow the application to share information to third-party applications on the device. | |
| Modificada | Alta (7.8) | 1.5% | — | Atlantiswordprocessor Atlantis Word Processor | 31/10/2019 | 17/6/2026 | An exploitable uninitialized pointer vulnerability exists in the Word document parser of the the Atlantis Word Processor. A specially crafted document can cause an array fetch to return an uninitialized pointer and then performs some arithmetic before writing a value to the result. Usage of this uninitialized pointer… | |
| Modificada | Media (5.9) | 0.40% | — | Microfocus Netiq Self Service Password Reset | 22/10/2019 | 17/6/2026 | Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack. | |
| Modificada | Media (5.5) | 0.34% | — | Symantec Norton Password Manager | 17/9/2019 | 17/6/2026 | Norton Password Manager, prior to 6.5.0.2104, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information. | |
| Modificada | Alta (7.8) | 1.6% | — | Trendmicro Password Manager | 20/8/2019 | 17/6/2026 | A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14684. | |
| Modificada | Alta (7.8) | 1.5% | — | Trendmicro Password Manager | 20/8/2019 | 17/6/2026 | A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687. | |
| Modificada | Alta (7) | 0.62% | 💥 PoC | Sailpoint Desktop Password Reset | 20/8/2019 | 17/6/2026 | An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only the Windows logon screen can escalate their privileges to NT AUTHORITY\System. An attacker would need local access to the machine for a successful exploit. The attacker must disconnect the computer… | |
| Modificada | Crítica (9.8) | 2.1% | — | Microfocus Netiq Self Service Password Reset | 14/8/2019 | 17/6/2026 | A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. Upgrade to Micro Focus Self Service Password Reset (SSPR) SSPR versions 4.4.0.3, 4.3.0.6, or 4.2.0.6 as appropriate. | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins Mask Passwords | 7/8/2019 | 17/6/2026 | Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure. | |
| Modificada | Media (6.1) | 1.9% | — | Antsword Project Antsword | 19/7/2019 | 17/6/2026 | In antSword before 2.1.0, self-XSS in the database configuration leads to code execution via modules/database/asp/index.js, modules/database/custom/index.js, modules/database/index.js, or modules/database/php/index.js. | |
| Modificada | Baja (3.9) | 0.26% | — | Norton Password Manager | 16/7/2019 | 17/6/2026 | Norton Password Manager, prior to 6.3.0.2082, may be susceptible to an address spoofing issue. This type of issue may allow an attacker to disguise their origin IP address in order to obfuscate the source of network traffic. | |
| Modificada | Media (6.1) | 0.81% | — | Keynto Team Password Manager | 9/7/2019 | 17/6/2026 | KEYNTO Team Password Manager 1.5.0 allows XSS because data saved from websites is mishandled in the online vault. | |
| Modificada | Crítica (9.8) | 3.3% | — | Strong Password Project Strong Password | 8/7/2019 | 17/6/2026 | The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 0.0.6. | |
| Modificada | Media (4.3) | 1.4% | — | Bcnquark Quarking Password Manager | 24/6/2019 | 17/6/2026 | BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_accessible_resources. An attacker can take advantage of this vulnerability and cause significant harm. | |
| Modificada | Alta (7.5) | 1.1% | — | Netiq Self Service Password Reset | 24/6/2019 | 17/6/2026 | An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be exploited to expose sensitive information. | |
| Modificada | Media (6.1) | 0.65% | — | Microfocus Netiq Self Service Password Reset | 24/6/2019 | 17/6/2026 | A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack. | |
| Modificada | Alta (7.8) | 1.7% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+14 | 18/6/2019 | 17/6/2026 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will… | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Cyberark Enterprise Password Vault | 8/5/2019 | 17/6/2026 | An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML authentication system. | |
| Modificada | Alta (7.5) | 1.3% | — | Symantec Norton Password Manager | 9/4/2019 | 17/6/2026 | Norton Password Manager may be susceptible to an address spoofing issue. This type of issue may allow an attacker to disguise their origin IP address in order to obfuscate the source of network traffic. | |
| Modificada | Media (6.5) | 2.5% | — | Uniqkey Password Manager | 8/4/2019 | 17/6/2026 | An issue was discovered in Uniqkey Password Manager 1.14. When entering new credentials to a site that isn't registered within this product, a pop-up window will appear asking the user if they want to save these new credentials. The code of the pop-up window can be read and, to some extent, manipulated by remote… | |
| Modificada | Media (6.5) | 2.7% | — | Uniqkey Password Manager | 8/4/2019 | 17/6/2026 | An issue was discovered in Uniqkey Password Manager 1.14. Upon entering new credentials to a site that is not registered within this product, a pop-up window will appear prompting the user if they want to save this new password. This pop-up window will persist on any page the user enters within the browser until a… |