Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1035 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.6%—Netwrix Password Secure3/4/202517/6/2026
Netwrix Password Secure 9.2.0.32454 allows OS command injection.
ModificadaMedia (6.9)0.56%—Phpgurukul BUS Pass Management System3/4/202517/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul Bus Pass Management System 1.0. This affects an unknown part of the file /view-pass-detail.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…
AplazadaAlta (8.6)0.55%—Labs64 PluginpassAI28/3/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 PluginPass pluginpass-pro-plugintheme-licensing allows Manipulating Web Input to File System Calls.This issue affects PluginPass: from n/a through <= 0.9.10.
AnalizadaMedia (6.9)0.69%—Oretnom23 Employee AND Visitor Gate Pass Logging System23/3/202517/6/2026
A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to exposure of information through directory listing. The attack can be launched remotely. The exploit has…
AnalizadaAlta (7.1)0.27%—Sjehutch Passbeemedia WEB Push Notification20/3/202517/6/2026
The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AnalizadaMedia (6.9)0.53%—Phpgurukul Curfew E-pass Management System17/3/202517/6/2026
A vulnerability classified as critical has been found in PHPGurukul Curfew e-Pass Management System 1.0. Affected is an unknown function of the file /admin/search-pass.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed…
AnalizadaCrítica (9.4)0.50%—Siemens Sipass Integrated Ac5102 (acc-g2) FirmwareSiemens Sipass Integrated Acc-ap Firmware11/3/202517/6/2026
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize input for the pubkey endpoint of the REST API. This could allow an authenticated remote administrator to escalate privileges by…
AnalizadaCrítica (9.3)0.18%—Siemens Sipass Integrated Ac5102 (acc-g2) FirmwareSiemens Sipass Integrated Acc-ap Firmware11/3/202517/6/2026
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize user input for specific commands on the telnet command line interface. This could allow an authenticated local administrator to…
AplazadaMedia (6.9)0.45%—Sipass Integrated Ac5102AISipass Integrated Acc-apAI11/3/202517/6/2026
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-AP (All versions < V6.4.8). Affected devices expose several MQTT URLs without authentication. This could allow an unauthenticated remote attacker to access sensitive data.
AnalizadaBaja (2.1)0.19%—Passbolt API10/3/202517/6/2026
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.
AnalizadaMedia (4.6)0.31%—Teampasswordmanager Team Password Manager4/3/202517/6/2026
A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page.
AnalizadaMedia (6.5)0.44%—Syspass28/2/202517/6/2026
The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.
AnalizadaMedia (5.4)0.26%—Syspass28/2/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component.
AnalizadaAlta (8.1)0.42%—Syspass28/2/202517/6/2026
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.
AnalizadaAlta (7.8)0.15%—Mongodb CompassRedhat Enterprise Linux FOR ARM 64Redhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux Server FOR Power Little Endian Update Services FOR SAP Solutions+127/2/202517/6/2026
MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
AnalizadaAlta (7.5)0.62%—Phusion Passenger24/2/202517/6/2026
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
AplazadaMedia (4.3)0.16%—Will Anderson Minimum-password-strengthAI24/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Will Anderson Minimum Password Strength minimum-password-strength allows Cross Site Request Forgery.This issue affects Minimum Password Strength: from n/a through <= 1.2.0.
AplazadaMedia (5.2)0.26%—Roboform Password ManagerAI17/2/202517/6/2026
Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an attacker with access to a device where the application is installed to bypass the lock screen and obtain sensitive information.
AnalizadaAlta (8.8)0.65%—Arubanetworks Clearpass Policy Manager4/2/202517/6/2026
A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying…
AnalizadaAlta (8.1)0.23%—Arubanetworks Clearpass Policy Manager4/2/202517/6/2026
A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could allow an attacker to perform a man-in-the-middle attack, potentially granting unauthorized access to network resources as well as enabling…
AnalizadaMedia (4.9)0.60%—Arubanetworks Clearpass Policy Manager4/2/202517/6/2026
A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directories containing sensitive information. If exploited successfully, this vulnerability allows an authenticated remote attacker with high privileges to access and retrieve sensitive data, potentially…
AnalizadaAlta (8.1)0.72%—Arubanetworks Clearpass Policy Manager4/2/202517/6/2026
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation…
AplazadaAlta (7.1)0.23%—WP Busters Passwordless WPAI27/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Busters Passwordless WP – Login with your glance or fingerprint passwordless-wp allows Reflected XSS.This issue affects Passwordless WP – Login with your glance or fingerprint: from n/a through <= 1.1.6.
AplazadaAlta (7.1)0.20%—Marcucci Password Protect PluginAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in marcucci Password Protect Plugin for WordPress password-protect-plugin-for-wordpress allows Stored XSS.This issue affects Password Protect Plugin for WordPress: from n/a through <= 0.8.1.0.
AnalizadaMedia (6.5)0.49%—Hirewebxperts Passwords Manager16/1/202517/6/2026
The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX actions in all versions up to, and including, 1.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
Orbitaley — Vulnerabilidades