Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1035 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.39%—Hirewebxperts Passwords Manager16/1/202517/6/2026
The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pms_save_setting' and 'post_new_pass' AJAX actions in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Subscriber-level access and…
AnalizadaAlta (7.5)0.51%—Hirewebxperts Passwords Manager16/1/202517/6/2026
The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fuctions in all versions up to, and including, 1.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (8.8)0.94%—Netvision AirpassAI16/1/202517/6/2026
The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
AplazadaCrítica (9.8)0.82%—Netvision AirpassAI16/1/202517/6/2026
The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access the specific administrative functionality to retrieve * all accounts and passwords.
AplazadaCrítica (9.8)0.55%—Netvision AirpassAI16/1/202517/6/2026
The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
AnalizadaMedia (4.8)0.27%—View Password Project View Password9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal View Password allows Cross-Site Scripting (XSS).This issue affects View Password: from 0.0.0 before 6.0.4.
AplazadaAlta (7.1)0.39%—Frankkoenen Ldap Login Password AND Role ManagerAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in frankkoenen ldap_login_password_and_role_manager ldap-login-password-and-role-manager allows Stored XSS.This issue affects ldap_login_password_and_role_manager: from n/a through <= 1.0.12.
AnalizadaAlta (7.5)0.40%—Wpchill Passster7/1/202517/6/2026
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted…
AplazadaMedia (5.7)0.21%—Apnotic Password PusherAI30/12/202417/6/2026
Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has been reported in versions 1.50.3 and prior where an attacker can copy the session cookie before a user logs out, potentially allowing session hijacking. Although the session token is replaced and…
AnalizadaAlta (8.1)0.47%—Teampass30/12/202417/6/2026
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.
AnalizadaMedia (5.3)0.31%—Teampass30/12/202417/6/2026
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager.
AnalizadaMedia (4.3)0.34%—Teampass30/12/202417/6/2026
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin.
AplazadaMedia (6.1)0.22%—Password FOR WPAI12/12/202417/6/2026
The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the get3_init_admin_page() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web…
AnalizadaMedia (6.3)0.41%—Arubanetworks Clearpass Policy Manager3/12/202417/6/2026
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying operating system.
AnalizadaMedia (5.4)0.27%—Arubanetworks Clearpass Policy Manager3/12/202417/6/2026
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful exploitation could enable a threat actor to perform any actions the user is authorized to do, including…
AnalizadaAlta (8)0.46%—Arubanetworks Clearpass Policy Manager3/12/202417/6/2026
An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
AnalizadaAlta (8.8)0.76%—Arubanetworks Clearpass Policy Manager3/12/202417/6/2026
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the underlying operating system.
AplazadaAlta (8.8)0.41%—Clickstudios PasswordstateAI29/11/202417/6/2026
In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.
AplazadaMedia (5.3)0.54%—Apnotic Password PusherAI20/11/202417/6/2026
Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable rate limiter. In versions prior to v1.49.0, the rate limiter could be bypassed by forging proxy headers allowing bad actors to send unlimited traffic to the site potentially causing a denial of…
AplazadaCrítica (9.6)0.80%💥 PoCGunghoinc Exclusive Content Password ProtectAI19/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in gunghoinc Exclusive Content Password Protect exclusive-content-password-protect allows Upload a Web Shell to a Web Server.This issue affects Exclusive Content Password Protect: from n/a through <= 1.1.0.
AplazadaAlta (7.5)0.56%—Labs64 DigipassAI14/11/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 DigiPass digipass allows Absolute Path Traversal.This issue affects DigiPass: from n/a through <= 0.3.0.
AplazadaAlta (7.1)0.27%—Techdabang User Password ResetAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techdabang User Password Reset user-password-reset allows Reflected XSS.This issue affects User Password Reset: from n/a through <= 1.0.
AplazadaAlta (7.1)0.34%—Apnotic Password PusherAI7/11/202417/6/2026
Password Pusher is an open source application to communicate sensitive information over the web. A cross-site scripting (XSS) vulnerability was identified in the PasswordPusher application, affecting versions `v1.41.1` through and including `v.1.48.0`. The issue arises from an un-sanitized parameter which could allow…
AnalizadaMedia (4.6)0.23%—Samsung Pass6/11/202417/6/2026
Improper authentication in Private Info in Samsung Pass in prior to version 4.4.04.7 allows physical attackers to access sensitive information in a specific scenario.
AplazadaCrítica (9.8)0.47%—Codepassenger JOB Board ManagerAI17/10/202417/6/2026
Incorrect Privilege Assignment vulnerability in CodePassenger Job Board Manager for WordPress jemployee allows Privilege Escalation.This issue affects Job Board Manager for WordPress: from n/a through <= 1.0.
Orbitaley — Vulnerabilidades