Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
336 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.5% | — | Zohocorp Manageengine Password Manager PRO | 15/12/2017 | 17/6/2026 | Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec. | |
| Modificada | Alta (7.5) | 1.4% | — | KED Password Manager Project KED Password Manager | 27/4/2017 | 17/6/2026 | kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the "password" command is used with an argument. The names of the password entries created and… | |
| Modificada | Alta (8) | 1.2% | — | Zohocorp Password Manager PRO | 20/4/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500). | |
| Modificada | Crítica (9.8) | 22% | 💥 Exploit | Trendmicro Password Manager | 12/4/2016 | 17/6/2026 | The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB. | |
| Modificada | Media (6.1) | 1.4% | — | Microfocus Self Service Password Reset | 24/3/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Crítica (10) | 2.4% | — | Dovestones AD Self Password Reset | 24/12/2015 | 17/6/2026 | The PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll in Dovestones AD Self Password Reset before 3.0.4.0 allows remote attackers to reset arbitrary passwords via a crafted request with a valid username. | |
| Modificada | Media (6.5) | 3.5% | — | Zohocorp Manageengine Password Manager PRO | 8/7/2015 | 17/6/2026 | SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PMP) before 8.1 Build 8101 allows remote authenticated users to execute arbitrary SQL commands via the ANDOR parameter, as demonstrated by a request to… | |
| Modificada | Baja (2.6) | 1.2% | — | Password Policy Project Password Policy | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x before 6.x-1.11 and 7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses the username constraint, allows remote attackers to inject arbitrary web script or HTML via a crafted username… | |
| Modificada | Media (6.4) | 2.4% | — | Manageengine Password Manager PRO | 16/12/2014 | 17/6/2026 | Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Zohocorp Manageengine Password Manager PROZohocorp Manageengine It360 | 5/12/2014 | 17/6/2026 | SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products,… | |
| Modificada | Alta (7.5) | 38% | 💥 Exploit | Manageengine It360Manageengine Password Manager PROManageengine Desktop Central | 5/12/2014 | 17/6/2026 | SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed… | |
| Modificada | Media (5) | 82% | 💥 Exploit | DrupalSecure Password Hashes Project Secure Passwords HashesDebian Linux | 24/11/2014 | 17/6/2026 | The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request. | |
| Modificada | Media (6.5) | 36% | 💥 Exploit | Manageengine Password Manager PRO | 17/11/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2)… | |
| Modificada | Media (6.5) | 13% | 💥 Exploit | Zohocorp Manageengine Password Manager PRO | 17/11/2014 | 17/6/2026 | SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Ireadercity Sword | 20/10/2014 | 17/6/2026 | The Sword (aka com.ireadercity.c25) application 3.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 14% | 💥 Exploit | Werdswords Download Shortcode | 3/9/2014 | 17/6/2026 | Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (4) | 1.2% | — | HP Icewall Identity ManagerHP Icewall SSO Password Reset Option | 5/4/2014 | 17/6/2026 | Unspecified vulnerability in HP IceWall Identity Manager 4.0 through SP1 and 5.0 and IceWall SSO 10.0 Password Reset Option, when Apache Commons FileUpload is used, allows remote authenticated users to cause a denial of service via unknown vectors. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | Dell Quest ONE Password Manager | 24/10/2013 | 17/6/2026 | The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's full name) by sending a login request with a valid domain and username but without the CaptchaType, UseCaptchaEveryTime, and CaptchaResponse parameters. | |
| Modificada | Baja (2.1) | 0.97% | — | Erikwebb Password Policy | 28/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the password_policy_admin_view function in password_policy.admin.inc in the Password Policy module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Administer policies" permission to inject arbitrary web script or HTML… | |
| Modificada | Media (4.3) | 0.98% | — | 1password | 28/12/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header that is not properly handled in a View Troubleshooting Report action. | |
| Modificada | Media (5) | 1.4% | — | Erikwebb Password Policy | 3/12/2012 | 16/6/2026 | The Password policy module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to obtain password hashes by sniffing the network, related to "client-side password history checks." | |
| Modificada | Media (6.8) | 0.70% | — | Erikwebb Password Policy | 20/9/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote attackers to hijack the authentication of administrative users for requests that unblock a user. | |
| Modificada | Baja (2.1) | 0.94% | — | Erik Webb Password Policy | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in password_policy.admin.inc in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote authenticated users with administer policies permissions to inject arbitrary web script or HTML via the name parameter. | |
| Modificada | Media (6.9) | 0.58% | — | Keepass Password Safe | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in KeePass Password Safe before 2.13 allows local users to gain privileges via a Trojan horse DwmApi.dll file in the current working directory, as demonstrated by a directory that contains a .kdbx file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 1.4% | — | Tinycouch Tiny Password | 14/3/2012 | 16/6/2026 | Unspecified vulnerability in the Tiny Password (com.tinycouch.android.freepassword) application 1.64 for Android has unknown impact and attack vectors. |