Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

336 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.2%—Uniqkey Password Manager5/4/201917/6/2026
Uniqkey Password Manager 1.14 contains a vulnerability because it fails to recognize the difference between domains and sub-domains. The vulnerability means that passwords saved for example.com will be recommended for usersite.example.com. This could lead to successful phishing campaigns and create a sense of false…
ModificadaMedia (5.5)0.43%—Agilebits 1password22/12/201817/6/2026
An issue was discovered in 1Password 7.2.3.BETA before 7.2.3.BETA-3 on macOS. A mistake in error logging resulted in instances where sensitive data passed from Safari to 1Password could be logged locally on the user's machine. This data could include usernames and passwords that a user manually entered into Safari.
ModificadaMedia (6.1)0.91%—Symantec Norton Password Manager6/12/201817/6/2026
Norton Password Manager for Android (formerly Norton Identity Safe) may be susceptible to a cross site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to…
ModificadaAlta (7.8)1.0%—Atlantiswordprocessor Atlantis Word Processor1/12/201817/6/2026
An exploitable uninitialized pointer vulnerability exists in the rich text format parser of Atlantis Word Processor, version 3.2.7.2. A specially crafted document can cause certain RTF tokens to dereference a pointer that has been uninitialized and then write to it. An attacker must convince a victim to open a…
ModificadaAlta (7.8)1.4%—Atlantiswordprocessor Atlantis Word Processor1/12/201817/6/2026
An exploitable out-of-bounds write vulnerability exists in the PNG implementation of Atlantis Word Processor, version 3.2.7.2. This can allow an attacker to corrupt memory, which can result in code execution under the context of the application. An attacker must convince a victim to open a specially crafted document…
ModificadaAlta (7.8)1.3%—Atlantiswordprocessor Atlantis Word Processor1/12/201817/6/2026
An exploitable arbitrary write vulnerability exists in the open document format parser of the Atlantis Word Processor, version 3.2.7.2, while trying to null-terminate a string. A specially crafted document can allow an attacker to pass an untrusted value as a length to a constructor. This constructor will miscalculate…
ModificadaMedia (5.9)7.9%💥 Exploit1password5/10/201817/6/2026
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity from an external application (since they are exported), it is…
ModificadaAlta (7.8)1.5%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable uninitialized pointer vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted document can cause an uninitialized pointer representing a TTableRow to be assigned to a variable on the stack. This variable is later dereferenced and then written…
ModificadaAlta (7.8)1.0%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable double-free vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted document can cause a TTableRow instance to be referenced twice, resulting in a double-free vulnerability when both the references go out of scope. An attacker must convince a…
ModificadaAlta (7.8)0.89%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable stack-based buffer overflow vulnerability exists in the JPEG parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted image embedded within a document can cause a length to be miscalculated and underflow. This length is then treated as unsigned and then used in a copying operation. Due to…
ModificadaAlta (7.8)1.0%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable heap-based buffer overflow vulnerability exists in the Windows enhanced metafile parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted image embedded within a document can cause an undersized allocation, resulting in an overflow when the application tries to copy data into it. An…
ModificadaAlta (7.8)1.4%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable uninitialized length vulnerability exists within the Word document-parser of the Atlantis Word Processor 3.0.2.3 and 3.0.2.5. A specially crafted document can cause Atlantis to skip initializing a value representing the number of columns of a table. Later, the application will use this as a length…
ModificadaAlta (7.8)1.3%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable arbitrary write vulnerability exists in the Word document parser of the Atlantis Word Processor 3.0.2.3 and 3.0.2.5. A specially crafted document can prevent Atlas from adding elements to an array that is indexed by a loop. When reading from this array, the application will use an out-of-bounds index…
ModificadaAlta (7.8)1.0%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable out-of-bounds write vulnerability exists in the Word Document parser of the Atlantis Word Processor 3.0.2.3, 3.0.2.5. A specially crafted document can cause Atlantis to write a value outside the bounds of a heap allocation, resulting in a buffer overflow. An attacker must convince a victim to open a…
ModificadaAlta (7.8)1.2%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable uninitialized variable vulnerability exists in the RTF-parsing functionality of Atlantis Word Processor 3.2.6 version. A specially crafted RTF file can leverage an uninitialized stack address, resulting in an out-of-bounds write, which in turn could lead to code execution.
ModificadaMedia (5.9)1.1%—Symantec Norton Password Manager29/8/201817/6/2026
The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials.
ModificadaMedia (5.4)0.53%—Clickstudios Passwordstate1/8/201817/6/2026
Click Studios Passwordstate before 8.3 Build 8397 allows XSS by authenticated users via an uploaded HTML document.
ModificadaMedia (4.3)0.58%—Pleasantsolutions Pleasant Password Server31/7/201817/6/2026
Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other users in Pleasant Password Server before 7.8.3.
ModificadaAlta (8.1)0.84%—Pleasantsolutions Pleasant Password Server31/7/201817/6/2026
Due to missing authorization checks, any authenticated user is able to list, upload, or delete attachments to password safe entries in Pleasant Password Server before 7.8.3. To perform those actions on an entry, the user needs to know the corresponding "CredentialId" value, which uniquely identifies a password safe…
ModificadaCrítica (9.8)4.6%—Simple Password Store Project Simple Password Store15/6/201817/6/2026
An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete regular expression, which allows remote attackers to spoof file signatures on configuration files and extension scripts. Modifying the…
ModificadaCrítica (9.8)2.8%—Ltb-project Ldap Tool BOX Self Service Password14/6/201817/6/2026
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.
ModificadaAlta (7.8)2.6%—Kaspersky Password Manager19/4/201817/6/2026
Unauthorized code execution from specific DLL and is known as DLL Hijacking attack in Kaspersky Password Manager versions before 8.0.6.538.
ModificadaCrítica (9.8)17%💥 ExploitCyberark Password Vault12/4/201817/6/2026
The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialized .NET object in an Authorization HTTP header.
ModificadaMedia (5.3)16%💥 ExploitCyberark Password Vault12/4/201817/6/2026
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message.
ModificadaCrítica (9.8)2.8%—Novosoft Handy Password10/1/201817/6/2026
A buffer overflow in Handy Password 4.9.3 allows remote attackers to execute arbitrary code via a long "Title name" field in "mail box" data that is mishandled in an "Open from mail box" action.
Orbitaley — Vulnerabilidades